WordPress
by WordPress
Source repositories
CVEs (374)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-4048 | Med | 0.30 | 5.7 | 0.02 | Jun 12, 2020 | In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions… | ||
| CVE-2024-31211 | Med | 0.29 | 5.5 | 0.03 | Apr 4, 2024 | WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected. | ||
| CVE-2023-5561 | Med | 0.28 | 5.3 | 0.04 | Oct 16, 2023 | WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack | ||
| CVE-2022-43504 | Med | 0.28 | 5.3 | 0.01 | Dec 5, 2022 | Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all… | ||
| CVE-2021-39200 | Med | 0.28 | 5.3 | 0.02 | Sep 9, 2021 | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to… | ||
| CVE-2020-28040 | Med | 0.28 | 4.3 | 0.01 | Nov 2, 2020 | WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. | ||
| CVE-2020-4046 | Med | 0.28 | 5.4 | 0.02 | Jun 12, 2020 | In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this could lead to script execution in… | ||
| CVE-2019-17674 | Med | 0.28 | 5.4 | 0.02 | Oct 17, 2019 | WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer. | ||
| CVE-2018-20153 | Med | 0.28 | 5.4 | 0.03 | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS. | ||
| CVE-2018-20149 | Med | 0.28 | 5.4 | 0.04 | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data. | ||
| CVE-2017-17094 | Med | 0.28 | 5.4 | 0.03 | Dec 2, 2017 | wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL. | ||
| CVE-2017-17093 | Med | 0.28 | 5.4 | 0.03 | Dec 2, 2017 | wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site. | ||
| CVE-2017-17092 | Med | 0.28 | 5.4 | 0.06 | Dec 2, 2017 | wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file. | ||
| CVE-2017-14725 | Med | 0.28 | 5.4 | 0.03 | Sep 23, 2017 | Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php. | ||
| CVE-2017-6817 | Med | 0.28 | 5.4 | 0.03 | Mar 12, 2017 | In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds. | ||
| CVE-2017-6814 | Med | 0.28 | 5.4 | 0.04 | Mar 12, 2017 | In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in… | ||
| CVE-2017-5610 | Med | 0.28 | 5.3 | 0.06 | Jan 30, 2017 | wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms. | ||
| CVE-2015-7989 | Med | 0.28 | 5.4 | 0.03 | May 22, 2016 | Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714. | ||
| CVE-2017-6816 | Med | 0.25 | 4.9 | 0.04 | Mar 12, 2017 | In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality. | ||
| CVE-2016-9263 | Med | 0.24 | 4.7 | 0.03 | Oct 12, 2017 | WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file. |
- risk 0.30cvss 5.7epss 0.02
In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions…
- risk 0.29cvss 5.5epss 0.03
WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.
- risk 0.28cvss 5.3epss 0.04
WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack
- risk 0.28cvss 5.3epss 0.01
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all…
- risk 0.28cvss 5.3epss 0.02
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to…
- risk 0.28cvss 4.3epss 0.01
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
- risk 0.28cvss 5.4epss 0.02
In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this could lead to script execution in…
- risk 0.28cvss 5.4epss 0.02
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
- risk 0.28cvss 5.4epss 0.03
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.
- risk 0.28cvss 5.4epss 0.04
In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.
- risk 0.28cvss 5.4epss 0.03
wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.
- risk 0.28cvss 5.4epss 0.03
wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.
- risk 0.28cvss 5.4epss 0.06
wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.
- risk 0.28cvss 5.4epss 0.03
Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
- risk 0.28cvss 5.4epss 0.03
In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
- risk 0.28cvss 5.4epss 0.04
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in…
- risk 0.28cvss 5.3epss 0.06
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
- risk 0.28cvss 5.4epss 0.03
Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.
- risk 0.25cvss 4.9epss 0.04
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
- risk 0.24cvss 4.7epss 0.03
WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.
Page 8 of 19