Wordpress

Wordpress

392 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 06.10.2026 17:48:37
  • Zuletzt bearbeitet 06.10.2026 21:17:20

Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data. This issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6...

Warnung Medienbericht
  • EPSS 2.88%
  • Veröffentlicht 22.09.2026 16:44:15
  • Zuletzt bearbeitet 28.09.2026 12:20:54

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this ca...

Medienbericht
  • EPSS 0.16%
  • Veröffentlicht 18.09.2026 06:00:05
  • Zuletzt bearbeitet 19.09.2026 15:17:08

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 ...

  • EPSS 0.44%
  • Veröffentlicht 09.09.2026 03:28:45
  • Zuletzt bearbeitet 09.09.2026 15:33:34

The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly into updat...

Medienbericht
  • EPSS 0.81%
  • Veröffentlicht 17.08.2026 20:55:33
  • Zuletzt bearbeitet 03.09.2026 17:02:54

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capabil...

Medienbericht
  • EPSS 0.89%
  • Veröffentlicht 07.08.2026 18:17:20
  • Zuletzt bearbeitet 03.09.2026 17:02:54

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions out...

Warnung Medienbericht
  • EPSS 73.1%
  • Veröffentlicht 17.07.2026 19:14:12
  • Zuletzt bearbeitet 29.07.2026 20:17:06

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Warnung Medienbericht
  • EPSS 95.61%
  • Veröffentlicht 17.07.2026 19:14:12
  • Zuletzt bearbeitet 22.07.2026 23:10:00

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and a...

  • EPSS 0.35%
  • Veröffentlicht 11.07.2026 03:44:25
  • Zuletzt bearbeitet 14.07.2026 15:17:10

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. Thi...

  • EPSS 0.2%
  • Veröffentlicht 09.07.2026 06:52:44
  • Zuletzt bearbeitet 09.07.2026 18:16:50

The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/advanced-search block in versions up to and including 5.0.31. This is due to insufficient input sanitiz...