← Back

Wordpress

wordpress

409 CVEs • 51 products

Products (51)

Click to collapse
Toggle
Wordpress
wordpress
Wordpress Mu
wordpress_mu
Blix
blix
Wassup Plugin
wassup_plugin
Blixed
blixed
Blixkrieg
blixkrieg
Unamed Theme
unamed_theme
Sirius
sirius
Pool
pool
Pictpress
pictpress
Wp Contactform
wp-contactform
Cryptographp
cryptographp
Captcha
captcha
Filemanager
filemanager
Wp Forum
wp_forum
Wp Cal Plugin
wp_cal_plugin
Adserve
adserve
Wordspew
wordspew
Wp Footnotes
wp-footnotes
Wp Download
wp_download
Wpss
wpss
Spambam Plugin
spambam_plugin
Fcchat Widget
fcchat_widget
Requests
requests
Debug Bar
debug_bar
Gutenberg
gutenberg

CVEs (409)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Oct 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Oct 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Oct 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Oct 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Oct 17, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Oct 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Oct 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 allows reflected XSS in the dashboard.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 allows XSS in shortcode previews.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 allows XSS in stored comments.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Sep 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
1Wordpress
1Wordpress
Nov 21, 2024
May 22, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.
1Wordpress
1Wordpress
Jun 17, 2026
Mar 14, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search...Show more
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php.Show less
1Wordpress
1Wordpress
Jun 17, 2026
Feb 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and...Show more
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.Show less
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Feb 20, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker...Show more
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.Show less
2Debian
Wordpress
2Debian Linux
Wordpress
Nov 21, 2024
Dec 14, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.
2Debian
Wordpress
2Debian Linux
Wordpress
Nov 21, 2024
Dec 14, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.