CVE-2023-38000
- EPSS 0.79%
- Veröffentlicht 13.10.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 08:12:40
Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.
CVE-2023-2745
- EPSS 79.53%
- Veröffentlicht 17.05.2023 09:15:10
- Zuletzt bearbeitet 08.04.2026 19:18:19
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload...
CVE-2023-22622
- EPSS 1.66%
- Veröffentlicht 05.01.2023 02:15:07
- Zuletzt bearbeitet 07.04.2025 19:15:49
WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a t...
CVE-2022-3590
- EPSS 3.15%
- Veröffentlicht 14.12.2022 09:15:09
- Zuletzt bearbeitet 21.04.2025 15:15:51
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
CVE-2022-43497
- EPSS 0.96%
- Veröffentlicht 05.12.2022 04:15:10
- Zuletzt bearbeitet 24.04.2025 14:15:37
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
CVE-2022-43500
- EPSS 0.73%
- Veröffentlicht 05.12.2022 04:15:10
- Zuletzt bearbeitet 24.04.2025 14:15:37
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
CVE-2022-43504
- EPSS 1.4%
- Veröffentlicht 05.12.2022 04:15:10
- Zuletzt bearbeitet 24.04.2025 14:15:37
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new p...
CVE-2011-1762
- EPSS 0.72%
- Veröffentlicht 18.04.2022 17:15:11
- Zuletzt bearbeitet 21.11.2024 01:26:59
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
CVE-2022-21662
- EPSS 64.53%
- Veröffentlicht 06.01.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:10
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can af...
CVE-2022-21663
- EPSS 3.7%
- Veröffentlicht 06.01.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:11
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. T...