Lucene search

K

Wordpress Security Vulnerabilities

cve
cve

CVE-2019-17674

WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.

5.4CVSS

6.8AI Score

0.002EPSS

2019-10-17 01:15 PM
181
cve
cve

CVE-2019-17675

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

8.8CVSS

9AI Score

0.002EPSS

2019-10-17 01:15 PM
370
2
cve
cve

CVE-2019-20041

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

9.8CVSS

9.2AI Score

0.009EPSS

2019-12-27 08:15 AM
254
3
cve
cve

CVE-2019-20042

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a...

6.1CVSS

6.7AI Score

0.002EPSS

2019-12-27 08:15 AM
125
cve
cve

CVE-2019-20043

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this al...

4.3CVSS

6.2AI Score

0.003EPSS

2019-12-27 08:15 AM
118
2
cve
cve

CVE-2019-8942

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image ...

8.8CVSS

7.8AI Score

0.943EPSS

2019-02-20 03:29 AM
268
cve
cve

CVE-2019-8943

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substrin...

6.5CVSS

6.4AI Score

0.928EPSS

2019-02-20 03:29 AM
217
3
cve
cve

CVE-2019-9787

WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. Th...

8.8CVSS

8.5AI Score

0.484EPSS

2019-03-14 04:29 PM
204
cve
cve

CVE-2020-11025

In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a min...

5.8CVSS

5.1AI Score

0.002EPSS

2020-04-30 10:15 PM
398
2
cve
cve

CVE-2020-11026

In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously ...

8.7CVSS

5.8AI Score

0.003EPSS

2020-04-30 11:15 PM
149
2
cve
cve

CVE-2020-11027

In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously af...

8.1CVSS

7.8AI Score

0.008EPSS

2020-04-30 11:15 PM
175
2
cve
cve

CVE-2020-11028

In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, ...

7.5CVSS

7.5AI Score

0.003EPSS

2020-04-30 11:15 PM
176
2
cve
cve

CVE-2020-11029

In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0...

6.1CVSS

6.2AI Score

0.006EPSS

2020-04-30 11:15 PM
220
2
cve
cve

CVE-2020-11030

In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This has been patched in version 5.4.1, along with all the previously affec...

6.4CVSS

5.3AI Score

0.001EPSS

2020-04-30 11:15 PM
136
cve
cve

CVE-2020-25286

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

5.3CVSS

5.5AI Score

0.001EPSS

2020-09-13 06:15 PM
127
2
cve
cve

CVE-2020-28032

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

9.8CVSS

9.3AI Score

0.008EPSS

2020-11-02 09:15 PM
185
4
cve
cve

CVE-2020-28033

WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

7.5CVSS

8.3AI Score

0.005EPSS

2020-11-02 09:15 PM
104
4
cve
cve

CVE-2020-28034

WordPress before 5.5.2 allows XSS associated with global variables.

6.1CVSS

7.2AI Score

0.035EPSS

2020-11-02 09:15 PM
132
4
cve
cve

CVE-2020-28035

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

9.8CVSS

9.3AI Score

0.005EPSS

2020-11-02 09:15 PM
194
cve
cve

CVE-2020-28036

wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

9.8CVSS

9.3AI Score

0.008EPSS

2020-11-02 09:15 PM
157
cve
cve

CVE-2020-28037

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

9.8CVSS

9.4AI Score

0.022EPSS

2020-11-02 09:15 PM
138
cve
cve

CVE-2020-28038

WordPress before 5.5.2 allows stored XSS via post slugs.

6.1CVSS

7.1AI Score

0.024EPSS

2020-11-02 09:15 PM
113
4
cve
cve

CVE-2020-28039

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

9.1CVSS

9.2AI Score

0.005EPSS

2020-11-02 09:15 PM
136
2
cve
cve

CVE-2020-28040

WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

4.3CVSS

6.4AI Score

0.009EPSS

2020-11-02 09:15 PM
97
4
cve
cve

CVE-2020-36326

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in saf...

9.8CVSS

8.7AI Score

0.007EPSS

2021-04-28 03:15 AM
471
18
cve
cve

CVE-2020-4046

In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this could lead to script execution in the editor/wp-admin...

5.4CVSS

5.2AI Score

0.004EPSS

2020-06-12 04:15 PM
107
2
cve
cve

CVE-2020-4047

In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has ...

6.8CVSS

6.4AI Score

0.001EPSS

2020-06-12 04:15 PM
105
2
cve
cve

CVE-2020-4048

In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release ...

5.7CVSS

5.9AI Score

0.001EPSS

2020-06-12 04:15 PM
177
2
cve
cve

CVE-2020-4049

In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been patched in version 5.4....

2.4CVSS

4.9AI Score

0.001EPSS

2020-06-12 04:15 PM
115
3
cve
cve

CVE-2020-4050

In affected versions of WordPress, misuse of the set-screen-option filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in ve...

3.5CVSS

5AI Score

0.001EPSS

2020-06-12 04:15 PM
154
2
cve
cve

CVE-2021-29447

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has b...

7.1CVSS

6.3AI Score

0.027EPSS

2021-04-15 09:15 PM
250
39
cve
cve

CVE-2021-29450

Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. I...

6.5CVSS

5.2AI Score

0.007EPSS

2021-04-15 10:15 PM
419
5
cve
cve

CVE-2021-29476

Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of Requests 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.

9.8CVSS

9.3AI Score

0.008EPSS

2021-04-27 09:15 PM
72
2
cve
cve

CVE-2021-39200

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to perform actions on y...

5.3CVSS

5.1AI Score

0.001EPSS

2021-09-09 10:15 PM
429
cve
cve

CVE-2021-39201

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions imposed on users who ...

7.6CVSS

5.2AI Score

0.001EPSS

2021-09-09 10:15 PM
355
cve
cve

CVE-2021-39202

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom...

7.6CVSS

5.3AI Score

0.001EPSS

2021-09-09 10:15 PM
50
cve
cve

CVE-2021-39203

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in the block editor under certain conditions. This aff...

6.8CVSS

6.2AI Score

0.001EPSS

2021-09-09 10:15 PM
54
2
cve
cve

CVE-2021-44223

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Dire...

9.8CVSS

9.4AI Score

0.008EPSS

2021-11-25 03:15 PM
624
2
cve
cve

CVE-2022-21661

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress ve...

8CVSS

7.9AI Score

0.915EPSS

2022-01-06 11:15 PM
437
2
cve
cve

CVE-2022-21662

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched...

8CVSS

5.5AI Score

0.004EPSS

2022-01-06 11:15 PM
312
In Wild
2
cve
cve

CVE-2022-21663

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. ...

7.2CVSS

7.2AI Score

0.004EPSS

2022-01-06 11:15 PM
229
2
cve
cve

CVE-2022-21664

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected ve...

8.8CVSS

8.7AI Score

0.005EPSS

2022-01-06 11:15 PM
439
cve
cve

CVE-2022-3590

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

5.9CVSS

5.6AI Score

0.001EPSS

2022-12-14 09:15 AM
483
cve
cve

CVE-2022-43497

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.

6.1CVSS

6AI Score

0.002EPSS

2022-12-05 04:15 AM
97
cve
cve

CVE-2022-43500

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.

6.1CVSS

6AI Score

0.002EPSS

2022-12-05 04:15 AM
114
cve
cve

CVE-2022-43504

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

5.3CVSS

5.3AI Score

0.002EPSS

2022-12-05 04:15 AM
108
cve
cve

CVE-2022-47161

Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.

8.8CVSS

8.8AI Score

0.001EPSS

2023-05-25 10:15 AM
100
cve
cve

CVE-2022-47174

Cross-Site Request Forgery (CSRF) vulnerability in WordPress Performance Team Performance Lab plugin <= 2.2.0 versions.

8.8CVSS

8.8AI Score

0.001EPSS

2023-05-25 01:15 PM
33
cve
cve

CVE-2023-22622

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide...

5.3CVSS

5.5AI Score

0.003EPSS

2023-01-05 02:15 AM
217
cve
cve

CVE-2023-2745

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such a...

5.4CVSS

5.4AI Score

0.004EPSS

2023-05-17 09:15 AM
898
Total number of security vulnerabilities404