CVE-2011-1762
- EPSS 0.42%
- Published 18.04.2022 17:15:11
- Last modified 21.11.2024 01:26:59
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
CVE-2022-21662
- EPSS 13.59%
- Published 06.01.2022 23:15:08
- Last modified 21.11.2024 06:45:10
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can af...
CVE-2022-21663
- EPSS 0.46%
- Published 06.01.2022 23:15:08
- Last modified 21.11.2024 06:45:11
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. T...
CVE-2022-21664
- EPSS 4.99%
- Published 06.01.2022 23:15:08
- Last modified 21.11.2024 06:45:11
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patc...
CVE-2022-21661
- EPSS 90.59%
- Published 06.01.2022 23:15:07
- Last modified 19.08.2025 16:35:50
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a c...
CVE-2021-44223
- EPSS 27.49%
- Published 25.11.2021 15:15:09
- Last modified 21.11.2024 06:30:36
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the na...
CVE-2021-39200
- EPSS 1.77%
- Published 09.09.2021 22:15:09
- Last modified 21.11.2024 06:18:52
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like no...
CVE-2021-39201
- EPSS 0.41%
- Published 09.09.2021 22:15:09
- Last modified 21.11.2024 06:18:53
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. Thi...
CVE-2021-39202
- EPSS 0.82%
- Published 09.09.2021 22:15:09
- Last modified 21.11.2024 06:18:53
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTM...
CVE-2021-39203
- EPSS 0.7%
- Published 09.09.2021 22:15:09
- Last modified 21.11.2024 06:18:53
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in th...