wordpress

412 tracked vulnerabilities.

CVE-2016-5834 MEDIUM
WordPress < 4.5.3 - Cross-Site Scripting via Crafted Attachment Name
Jun 29, 2016
CVSS 6.1
EPSS 0.01
CVE-2016-5833 MEDIUM
WordPress < 4.5.3 - Cross-Site Scripting via Crafted Attachment Name
Jun 29, 2016
CVSS 6.1
EPSS 0.01
CVE-2016-5832 HIGH
WordPress < 4.5.3 - Open Redirect via Customizer
Jun 29, 2016
CVSS 7.5
EPSS 0.02
CVE-2016-4567 MEDIUM
MediaElement.js < 2.21.0 - Cross-Site Scripting via FlashMediaElement.as jsinitfunction Parameter
May 22, 2016
CVSS 6.1
EPSS 0.04
CVE-2016-4566 MEDIUM
WordPress < 4.5.2 - Cross-Site Scripting via Plupload Flash Component
May 22, 2016
CVSS 6.1
EPSS 0.05
CVE-2016-2222 HIGH
WordPress < 4.4.2 - Server-Side Request Forgery via IPv4 Address in u Parameter
May 22, 2016
CVSS 8.6
EPSS 0.05
CVE-2016-2221 HIGH
WordPress < 4.4.2 - Open Redirect via Malformed URL Hostname Parsing
May 22, 2016
CVSS 7.4
EPSS 0.03
CVE-2016-1564 MEDIUM
WordPress < 4.4.1 - Cross-Site Scripting via Stylesheet or Template Name
May 22, 2016
CVSS 6.1
EPSS 0.01
CVE-2015-8834 MEDIUM
WordPress < 4.2.2 - Cross-Site Scripting via Long Comment Storage
May 22, 2016
CVSS 6.1
EPSS 0.01
CVE-2015-7989 MEDIUM
WordPress < 4.3.1 - Authenticated Cross-Site Scripting via User Email Address
May 22, 2016
CVSS 5.4
EPSS 0.00
CVE-2015-5715 MEDIUM
WordPress < 4.3.1 - Authenticated Access Bypass via XMLRPC Post Editing
May 22, 2016
CVSS 4.3
EPSS 0.29
CVE-2015-5714 MEDIUM
WordPress < 4.3.1 - Cross-Site Scripting via Shortcode Tag Processing
May 22, 2016
CVSS 6.1
EPSS 0.31
CVE-2015-5734
WordPress < 4.2.3 - Cross-Site Scripting in Legacy Theme Preview
Nov 09, 2015
EPSS 0.03
CVE-2015-5733
WordPress < 4.2.4 - Cross-Site Scripting via Accessibility Helper Title
Nov 09, 2015
EPSS 0.02
CVE-2015-5732
WordPress < 4.2.3 - Cross-Site Scripting via Widget Title
Nov 09, 2015
EPSS 0.02
CVE-2015-5731
WordPress < 4.2.3 - Cross-Site Request Forgery via Post Lock Action
Nov 09, 2015
EPSS 0.15
CVE-2015-5730
WordPress < 4.2.4 - Timing Side-Channel Attack via Widget Instance Sanitization
Nov 09, 2015
EPSS 0.10
CVE-2015-2213
WordPress < 4.2.3 - SQL Injection via Trashed Comment Handling
Nov 09, 2015
EPSS 0.21
CVE-2015-3439
Ephox plupload.flash.swf shim 2.1.2 - XSS
Aug 05, 2015
EPSS 0.03
CVE-2015-3438
WordPress < 4.1.2 - Cross-Site Scripting via UTF-8 Character Handling
Aug 05, 2015
EPSS 0.02
CVE-2015-5623
WordPress < 4.2.3 - Authenticated Improper Access Control via Post Quickdraft Save
Aug 03, 2015
EPSS 0.48
CVE-2015-5622
WordPress < 4.2.3 - Authenticated Cross-Site Scripting via Shortcode in HTML Element
Aug 03, 2015
EPSS 0.01
CVE-2015-3440
WordPress <4.2.1 - XSS
Aug 03, 2015
EPSS 0.14
CVE-2014-6412 HIGH
WordPress < 4.4.0 - Weak Password Recovery Token Generation
Apr 12, 2018
CVSS 8.1
EPSS 0.02
CVE-2014-9039
WordPress <4.0.1 - Remote Code Execution
Nov 25, 2014
EPSS 0.02