Wordpress

Wordpress

388 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.81%
  • Veröffentlicht 17.08.2026 20:55:33
  • Zuletzt bearbeitet 18.08.2026 16:18:12

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capabil...

Medienbericht
  • EPSS 0.89%
  • Veröffentlicht 07.08.2026 18:17:20
  • Zuletzt bearbeitet 07.08.2026 19:18:51

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions out...

Warnung Medienbericht
  • EPSS 73.1%
  • Veröffentlicht 17.07.2026 19:14:12
  • Zuletzt bearbeitet 29.07.2026 20:17:06

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Warnung Medienbericht
  • EPSS 95.61%
  • Veröffentlicht 17.07.2026 19:14:12
  • Zuletzt bearbeitet 22.07.2026 23:10:00

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and a...

  • EPSS 0.35%
  • Veröffentlicht 11.07.2026 03:44:25
  • Zuletzt bearbeitet 14.07.2026 15:17:10

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. Thi...

  • EPSS 0.2%
  • Veröffentlicht 09.07.2026 06:52:44
  • Zuletzt bearbeitet 09.07.2026 18:16:50

The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/advanced-search block in versions up to and including 5.0.31. This is due to insufficient input sanitiz...

  • EPSS 0.41%
  • Veröffentlicht 06.06.2026 02:28:35
  • Zuletzt bearbeitet 23.07.2026 07:10:00

The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortcode 'num' parameter in all versions up to, and including, 4.38. This is due to insufficient escaping when embedding user-supplied sho...

  • EPSS 0.54%
  • Veröffentlicht 05.06.2026 18:31:11
  • Zuletzt bearbeitet 05.06.2026 19:20:19

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.38. This is due to the ajax_run_tool() AJAX ...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 17.05.2026 12:11:30
  • Zuletzt bearbeitet 18.05.2026 17:05:46

Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspath parameter on PHP versions before 5.3.4. Attackers...

  • EPSS 0.31%
  • Veröffentlicht 11.03.2026 09:25:44
  • Zuletzt bearbeitet 22.04.2026 21:27:27

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, t...