Wordpress

Wordpress

360 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.03%
  • Published 28.04.2021 03:15:07
  • Last modified 21.11.2024 05:29:17

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were alway...

  • EPSS 2.08%
  • Published 15.04.2021 22:15:12
  • Last modified 21.11.2024 06:01:07

Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with ...

Exploit
  • EPSS 90.58%
  • Published 15.04.2021 21:15:17
  • Last modified 21.11.2024 06:01:07

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files i...

  • EPSS 16.02%
  • Published 02.11.2020 21:15:31
  • Last modified 21.11.2024 05:22:15

WordPress before 5.5.2 allows stored XSS via post slugs.

  • EPSS 6%
  • Published 02.11.2020 21:15:31
  • Last modified 21.11.2024 05:22:15

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

  • EPSS 0.31%
  • Published 02.11.2020 21:15:31
  • Last modified 21.11.2024 05:22:15

WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

  • EPSS 20.72%
  • Published 02.11.2020 21:15:30
  • Last modified 21.11.2024 05:22:14

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

  • EPSS 1.26%
  • Published 02.11.2020 21:15:30
  • Last modified 21.11.2024 05:22:14

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

  • EPSS 2.68%
  • Published 02.11.2020 21:15:30
  • Last modified 21.11.2024 05:22:14

WordPress before 5.5.2 allows XSS associated with global variables.

  • EPSS 4.88%
  • Published 02.11.2020 21:15:30
  • Last modified 21.11.2024 05:22:14

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.