Wordpress

Wordpress

360 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Media report
  • EPSS 7.37%
  • Published 14.12.2018 20:29:00
  • Last modified 21.11.2024 04:00:57

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

Media report
  • EPSS 6.8%
  • Published 14.12.2018 20:29:00
  • Last modified 21.11.2024 04:00:57

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the p...

Media report
  • EPSS 11.68%
  • Published 14.12.2018 20:29:00
  • Last modified 21.11.2024 04:00:57

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

Media report
  • EPSS 5.38%
  • Published 14.12.2018 20:29:00
  • Last modified 21.11.2024 04:00:57

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

  • EPSS 1.35%
  • Published 16.11.2018 09:29:00
  • Last modified 21.11.2024 03:57:41

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

  • EPSS 31.15%
  • Published 06.09.2018 16:29:05
  • Last modified 21.11.2024 03:40:22

WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail u...

  • EPSS 23.44%
  • Published 06.09.2018 12:29:00
  • Last modified 21.11.2024 03:04:54

WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional p...

  • EPSS 2.51%
  • Published 10.08.2018 16:29:00
  • Last modified 21.11.2024 03:48:28

In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in a predictable wp-content/uplo...

Exploit
  • EPSS 46.2%
  • Published 26.06.2018 20:29:00
  • Last modified 21.11.2024 03:46:03

WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to mis...

  • EPSS 6.6%
  • Published 16.04.2018 09:58:09
  • Last modified 21.11.2024 03:40:49

Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.