Wordpress

Wordpress

377 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.31%
  • Veröffentlicht 06.01.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:11

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. T...

  • EPSS 3.74%
  • Veröffentlicht 06.01.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:11

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patc...

Exploit
  • EPSS 90.37%
  • Veröffentlicht 06.01.2022 23:15:07
  • Zuletzt bearbeitet 19.08.2025 16:35:50

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a c...

Exploit
  • EPSS 27.49%
  • Veröffentlicht 25.11.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 06:30:36

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the na...

  • EPSS 1.77%
  • Veröffentlicht 09.09.2021 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:52

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like no...

  • EPSS 0.5%
  • Veröffentlicht 09.09.2021 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:53

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. Thi...

  • EPSS 0.82%
  • Veröffentlicht 09.09.2021 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:53

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTM...

  • EPSS 1.23%
  • Veröffentlicht 09.09.2021 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:53

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in th...

  • EPSS 0.3%
  • Veröffentlicht 28.04.2021 03:15:07
  • Zuletzt bearbeitet 21.11.2024 05:29:17

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were alway...

  • EPSS 2.22%
  • Veröffentlicht 27.04.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:01:13

Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.