CVE-2016-6896
- EPSS 24.3%
- Published 18.01.2017 21:59:00
- Last modified 20.04.2025 01:37:25
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugi...
CVE-2016-6897
- EPSS 30.26%
- Published 18.01.2017 21:59:00
- Last modified 20.04.2025 01:37:25
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by...
CVE-2017-5492
- EPSS 0.53%
- Published 15.01.2017 02:59:03
- Last modified 20.04.2025 01:37:25
Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, ...
CVE-2017-5493
- EPSS 1.67%
- Published 15.01.2017 02:59:03
- Last modified 20.04.2025 01:37:25
wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or...
CVE-2017-5487
- EPSS 92.57%
- Published 15.01.2017 02:59:02
- Last modified 20.04.2025 01:37:25
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp...
CVE-2017-5488
- EPSS 0.88%
- Published 15.01.2017 02:59:02
- Last modified 20.04.2025 01:37:25
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.
CVE-2017-5489
- EPSS 0.51%
- Published 15.01.2017 02:59:02
- Last modified 20.04.2025 01:37:25
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.
CVE-2017-5490
- EPSS 1.31%
- Published 15.01.2017 02:59:02
- Last modified 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, rela...
CVE-2017-5491
- EPSS 1.62%
- Published 15.01.2017 02:59:02
- Last modified 20.04.2025 01:37:25
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
CVE-2016-7168
- EPSS 0.65%
- Published 05.01.2017 02:59:03
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an i...