Wordpress

Wordpress

360 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 84.59%
  • Published 05.03.2007 20:19:00
  • Last modified 09.04.2025 00:30:58

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ...

Exploit
  • EPSS 7.7%
  • Published 03.03.2007 19:19:00
  • Last modified 09.04.2025 00:30:58

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue ...

  • EPSS 0.56%
  • Published 02.03.2007 22:19:00
  • Last modified 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability t...

Exploit
  • EPSS 6%
  • Published 21.02.2007 17:28:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML vi...

  • EPSS 1.33%
  • Published 29.01.2007 17:28:00
  • Last modified 09.04.2025 00:30:58

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download ...

  • EPSS 7.76%
  • Published 29.01.2007 17:28:00
  • Last modified 09.04.2025 00:30:58

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usa...

  • EPSS 1.25%
  • Published 29.01.2007 17:28:00
  • Last modified 09.04.2025 00:30:58

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for ...

  • EPSS 0.93%
  • Published 16.01.2007 23:28:00
  • Last modified 09.04.2025 00:30:58

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the pat...

  • EPSS 11.18%
  • Published 13.01.2007 02:28:00
  • Last modified 09.04.2025 00:30:58

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL co...

  • EPSS 1.43%
  • Published 09.01.2007 00:28:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable ...