CVE-2019-17673
- EPSS 5.46%
- Published 17.10.2019 13:15:11
- Last modified 21.11.2024 04:32:45
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
CVE-2019-17674
- EPSS 3.34%
- Published 17.10.2019 13:15:11
- Last modified 21.11.2024 04:32:45
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
CVE-2019-17675
- EPSS 4.65%
- Published 17.10.2019 13:15:11
- Last modified 21.11.2024 04:32:45
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
CVE-2019-17669
- EPSS 12.19%
- Published 17.10.2019 13:15:10
- Last modified 21.11.2024 04:32:44
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
CVE-2019-17670
- EPSS 5.32%
- Published 17.10.2019 13:15:10
- Last modified 21.11.2024 04:32:44
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
CVE-2019-17671
- EPSS 72.49%
- Published 17.10.2019 13:15:10
- Last modified 21.11.2024 04:32:44
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
CVE-2019-16221
- EPSS 2.45%
- Published 11.09.2019 14:15:12
- Last modified 21.11.2024 04:30:18
WordPress before 5.2.3 allows reflected XSS in the dashboard.
CVE-2019-16222
- EPSS 2.96%
- Published 11.09.2019 14:15:12
- Last modified 21.11.2024 04:30:18
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
CVE-2019-16223
- EPSS 5.71%
- Published 11.09.2019 14:15:12
- Last modified 21.11.2024 04:30:18
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
CVE-2019-16217
- EPSS 3.05%
- Published 11.09.2019 14:15:11
- Last modified 21.11.2024 04:30:17
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.