Skip to main content

Vendor archive

wordpress CVEs

Beta · best-effort

627 CVEs tagged to vendor wordpress36 Critical, 136 High, 429 Medium, 26 Low, 0 Unrated.

CVE-2012-5868

Published Dec 27, 2012

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session iden…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5469

Published Dec 20, 2012

The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a direct request to wp-content/…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5178

Published Dec 19, 2012

Cross-site request forgery (CSRF) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to hijack the authentication of arbitrary users for reques…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5226

Published Oct 25, 2012

Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to hijack the authentication of an adm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5225

Published Oct 25, 2012

Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via un…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5216

Published Oct 25, 2012

SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the active par…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5328

Published Oct 8, 2012

Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress might allow remote authenticated users to execute arbitra…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5327

Published Oct 8, 2012

Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5208

Published Oct 8, 2012

Multiple directory traversal vulnerabilities in the BackWPup plugin before 1.4.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the wpabs param…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 627 CVEsPage 13 of 26