wordpress
412 tracked vulnerabilities.
CVE-2019-8943
MEDIUM
NUCLEI
WordPress <= 5.0.3 - Authenticated Path Traversal via Image Crop Filename
Feb 20, 2019
CVSS 6.5
EPSS 0.94
CVE-2019-8942
HIGH
WordPress < 4.9.9 and 5.x < 5.0.1 - Authenticated Remote Code Execution via Image Metadata
Feb 20, 2019
CVSS 8.8
EPSS 0.94
CVE-2018-20153
MEDIUM
WordPress < 4.9.9 and 5.x < 5.0.1 - Cross-Site Scripting via Comment Modification
Dec 14, 2018
CVSS 5.4
EPSS 0.05
CVE-2018-20152
MEDIUM
WordPress <4.9.9 & <5.0.1 - Auth Bypass
Dec 14, 2018
CVSS 6.5
EPSS 0.12
CVE-2018-20151
HIGH
WordPress <4.9.9, 5.x <5.0.1 - Info Disclosure
Dec 14, 2018
CVSS 7.5
EPSS 0.07
CVE-2018-20150
MEDIUM
WordPress <4.9.9 & 5.x <5.0.1 - XSS
Dec 14, 2018
CVSS 6.1
EPSS 0.07
CVE-2018-20149
MEDIUM
WordPress < 4.9.9 and 5.x < 5.0.1 - Cross-Site Scripting via Crafted File Upload
Dec 14, 2018
CVSS 5.4
EPSS 0.04
CVE-2018-20148
CRITICAL
WordPress <4.9.9, 5.x <5.0.1 - Code Injection
Dec 14, 2018
CVSS 9.8
EPSS 0.55
CVE-2018-20147
MEDIUM
WordPress <4.9.9 & <5.0.1 - Auth Bypass
Dec 14, 2018
CVSS 6.5
EPSS 0.06
CVE-2018-19296
HIGH
PHPMailer <5.2.27, <6.0.6 - Code Injection
Nov 16, 2018
CVSS 8.8
EPSS 0.02
CVE-2018-1000773
HIGH
WordPress < 4.9.8 - Authenticated Remote Code Execution via Thumbnail Processing
Sep 06, 2018
CVSS 8.8
EPSS 0.28
CVE-2018-14028
HIGH
WordPress 4.9.7 - Authenticated Unrestricted PHP File Upload via Plugin Uploader
Aug 10, 2018
CVSS 7.2
EPSS 0.02
CVE-2018-12895
HIGH
WordPress <= 4.9.6 - Authenticated Arbitrary File Deletion via Post Thumbnail Parameter
Jun 26, 2018
CVSS 8.8
EPSS 0.89
CVE-2018-10102
MEDIUM
WordPress < 4.9.5 - Cross-Site Scripting via Generator Tag
Apr 16, 2018
CVSS 6.1
EPSS 0.05
CVE-2018-10101
MEDIUM
WordPress < 4.9.5 - Open Redirect via Localhost URL Validation
Apr 16, 2018
CVSS 6.1
EPSS 0.09
CVE-2018-10100
MEDIUM
WordPress < 4.9.5 - Open Redirect via Login Page HTTPS Redirection
Apr 16, 2018
CVSS 6.1
EPSS 0.07
CVE-2018-6389
HIGH
WordPress < 4.9.2 - Unauthenticated Denial of Service via Repeated JavaScript File Loading
Feb 06, 2018
CVSS 7.5
EPSS 0.87
CVE-2018-5776
MEDIUM
WordPress < 4.9.2 - Cross-Site Scripting in MediaElement Flash Fallback Files
Jan 18, 2018
CVSS 6.1
EPSS 0.03
CVE-2017-6514
MEDIUM
WordPress 4.7.2 - Path Disclosure via OEmbed Endpoint
May 22, 2019
CVSS 5.3
EPSS 0.01
CVE-2017-1000600
HIGH
WordPress < 4.9 - Authenticated Remote Code Execution via Thumbnail Processing
Sep 06, 2018
CVSS 8.8
EPSS 0.20
CVE-2017-17094
MEDIUM
WordPress < 4.9.1 - Cross-Site Scripting via RSS and Atom Feed Enclosures
Dec 02, 2017
CVSS 5.4
EPSS 0.08
CVE-2017-17093
MEDIUM
WordPress < 4.9.1 - Cross-Site Scripting via Lang Attribute
Dec 02, 2017
CVSS 5.4
EPSS 0.08
CVE-2017-17092
MEDIUM
NUCLEI
WordPress < 4.9.1 - Authenticated JavaScript File Upload
Dec 02, 2017
CVSS 5.4
EPSS 0.05
CVE-2017-17091
HIGH
WordPress < 4.9.1 - Use of Insufficiently Random Values in User ID Key Generation
Dec 02, 2017
CVSS 8.8
EPSS 0.03
CVE-2017-16510
CRITICAL
WordPress < 4.8.3 - SQL Injection via Double Prepare Approach
Nov 02, 2017
CVSS 9.8
EPSS 0.04
Products
wordpress 353
wordpress_mu 10
WordPress 3
sniplets_plugin 3
blix 2
math_comment_spam_protection_plugin 2
pay-with-tweet 2
wassup_plugin 2
Buddypress 1
Social-Share-Buttons 1
adserve 1
alert_before_you_post 1
blixed 1
blixkrieg 1
blogger_importer 1
captcha 1
cryptographp 1
dean_logan_wp-people_plugin 1
debug_bar 1
download_monitor_plugin 1
fcchat_widget 1
filemanager 1
gutenberg 1
health_check_\&_troubleshooting 1
lanoba_social_plugin 1
page_flip_image_gallery_plugin 1
performance_lab 1
permalinks_migration_plugin 1
peter\'s_math_anti-spam_for_wordpress 1
photo_album_plugin 1
Quick Filters