Wordpress

Wordpress

377 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 11.03.2026 09:25:44
  • Zuletzt bearbeitet 22.04.2026 21:27:27

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, t...

  • EPSS 0.17%
  • Veröffentlicht 09.12.2025 13:51:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in the 'trim_text' function in all versions up to, and including, 2.5 due to insufficient input sanitization and output esca...

  • EPSS 0.03%
  • Veröffentlicht 23.09.2025 19:15:41
  • Zuletzt bearbeitet 28.04.2026 19:34:13

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requir...

  • EPSS 0.04%
  • Veröffentlicht 23.09.2025 18:15:37
  • Zuletzt bearbeitet 28.04.2026 19:34:06

Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contri...

  • EPSS 0.07%
  • Veröffentlicht 21.07.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.

  • EPSS 1.78%
  • Veröffentlicht 17.07.2025 01:44:54
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input passed direc...

Exploit
  • EPSS 0.85%
  • Veröffentlicht 15.05.2025 20:15:59
  • Zuletzt bearbeitet 28.05.2025 15:42:01

The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

  • EPSS 0.18%
  • Veröffentlicht 13.03.2025 02:15:13
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'text' and 'id' parameters of the limpia() function in all versions up to, and including, 1.0.8 due to insufficient escaping on the user supplied parameter and la...

  • EPSS 0.29%
  • Veröffentlicht 24.01.2025 18:15:35
  • Zuletzt bearbeitet 23.04.2026 15:25:04

Missing Authorization vulnerability in patreon Patreon WordPress patreon-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Patreon WordPress: from n/a through <= 1.9.1.

  • EPSS 1.42%
  • Veröffentlicht 23.11.2024 10:15:03
  • Zuletzt bearbeitet 12.07.2025 00:29:04

The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wtab' parameter in versions 3.0.8 to 3.1.2 due to insufficient input sanitization and output escaping. This m...