CVE-2014-5205
- EPSS 0.14%
- Veröffentlicht 18.08.2014 11:15:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack...
CVE-2014-0166
- EPSS 34.83%
- Veröffentlicht 10.04.2014 00:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a f...
- EPSS 0.71%
- Veröffentlicht 10.04.2014 00:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.
CVE-2010-5293
- EPSS 0.39%
- Veröffentlicht 21.01.2014 01:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a sub...
CVE-2010-5294
- EPSS 0.71%
- Veröffentlicht 21.01.2014 01:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error messag...
CVE-2010-5295
- EPSS 0.5%
- Veröffentlicht 21.01.2014 01:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.
CVE-2010-5296
- EPSS 0.4%
- Veröffentlicht 21.01.2014 01:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrict...
CVE-2010-5297
- EPSS 0.23%
- Veröffentlicht 21.01.2014 01:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunis...
- EPSS 0.51%
- Veröffentlicht 21.01.2014 01:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.
CVE-2012-6633
- EPSS 0.39%
- Veröffentlicht 21.01.2014 01:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.