Wordpress

Wordpress

388 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.79%
  • Veröffentlicht 13.10.2023 10:15:09
  • Zuletzt bearbeitet 21.11.2024 08:12:40

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.

  • EPSS 79.53%
  • Veröffentlicht 17.05.2023 09:15:10
  • Zuletzt bearbeitet 08.04.2026 19:18:19

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload...

  • EPSS 1.66%
  • Veröffentlicht 05.01.2023 02:15:07
  • Zuletzt bearbeitet 07.04.2025 19:15:49

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a t...

Exploit
  • EPSS 3.15%
  • Veröffentlicht 14.12.2022 09:15:09
  • Zuletzt bearbeitet 21.04.2025 15:15:51

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

  • EPSS 0.96%
  • Veröffentlicht 05.12.2022 04:15:10
  • Zuletzt bearbeitet 24.04.2025 14:15:37

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.

  • EPSS 0.73%
  • Veröffentlicht 05.12.2022 04:15:10
  • Zuletzt bearbeitet 24.04.2025 14:15:37

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.

  • EPSS 1.4%
  • Veröffentlicht 05.12.2022 04:15:10
  • Zuletzt bearbeitet 24.04.2025 14:15:37

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new p...

  • EPSS 0.72%
  • Veröffentlicht 18.04.2022 17:15:11
  • Zuletzt bearbeitet 21.11.2024 01:26:59

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.

  • EPSS 64.53%
  • Veröffentlicht 06.01.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:10

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can af...

Exploit
  • EPSS 3.7%
  • Veröffentlicht 06.01.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:11

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. T...