Wordpress
wordpress
409 CVEs • 51 products
Products (51)
Click to collapseToggle
Products (51)
Click to collapse
CVEs (409)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-m...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins. |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// U...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files. |
4Debian FedoraprojectPhpmailer Project+1 more4Debian Linux FedoraPhpmailer+1 moreNov 21, 2024 Nov 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. |
WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to...Show more |
WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated use...Show more |
In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Jun 26, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.ph...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Apr 16, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag. |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Apr 16, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server. |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Apr 16, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS. |
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach. |
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of req...Show more |
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement). |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Dec 2, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Dec 2, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Dec 2, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file. |
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this st...Show more |