Lucene search

K

Wordpress Security Vulnerabilities

cve
cve

CVE-2023-38000

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.

6.5CVSS

5.3AI Score

0.001EPSS

2023-10-13 10:15 AM
131
cve
cve

CVE-2023-39999

Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 t...

4.3CVSS

4.7AI Score

0.002EPSS

2023-10-13 12:15 PM
178
In Wild
cve
cve

CVE-2023-5561

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

5.3CVSS

5.3AI Score

0.001EPSS

2023-10-16 08:15 PM
173
cve
cve

CVE-2024-3936

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtTPGSaveSettings function in all versions up to, and including, 7.6.1. This makes it possible for authe...

4.3CVSS

6.3AI Score

0.001EPSS

2024-05-02 05:15 PM
41
Total number of security vulnerabilities404