CVE-2016-7169
- EPSS 3.02%
- Veröffentlicht 05.01.2017 02:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafte...
CVE-2016-10033
- EPSS 94.43%
- Veröffentlicht 30.12.2016 19:59:00
- Zuletzt bearbeitet 08.07.2025 01:00:02
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
CVE-2016-10045
- EPSS 93.6%
- Veröffentlicht 30.12.2016 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal esca...
CVE-2016-6635
- EPSS 0.29%
- Veröffentlicht 07.08.2016 16:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change ...
CVE-2016-6634
- EPSS 0.78%
- Veröffentlicht 07.08.2016 16:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-4029
- EPSS 0.53%
- Veröffentlicht 07.08.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.
CVE-2016-5839
- EPSS 1.12%
- Veröffentlicht 29.06.2016 14:10:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.
CVE-2016-5838
- EPSS 1.73%
- Veröffentlicht 29.06.2016 14:10:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.
CVE-2016-5837
- EPSS 0.83%
- Veröffentlicht 29.06.2016 14:10:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.
CVE-2016-5836
- EPSS 7.25%
- Veröffentlicht 29.06.2016 14:10:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.