whyisjake

4 exploits Active since Sep 2019
CVE-2019-16222 WRITEUP MEDIUM WRITEUP
WordPress <5.2.3 - XSS
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
CVSS 6.1
CVE-2019-17669 WRITEUP CRITICAL WRITEUP
Wordpress < 5.2.4 - SSRF
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
CVSS 9.8
CVE-2019-17673 WRITEUP HIGH WRITEUP
WordPress <5.2.4 - Info Disclosure
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
CVSS 7.5
CVE-2019-17675 WRITEUP HIGH WRITEUP
Wordpress < 5.2.4 - CSRF
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
CVSS 8.8