Skip to main content

Vendor archive

wordpress CVEs

Beta · best-effort

627 CVEs tagged to vendor wordpress36 Critical, 136 High, 429 Medium, 26 Low, 0 Unrated.

CVE-2011-4342

Published Oct 8, 2012

PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4448

Published Sep 28, 2012

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that m…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5194

Published Sep 23, 2012

Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5193

Published Sep 23, 2012

Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote a…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-5180

Published Sep 20, 2012

Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4422

Published Sep 14, 2012

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activat…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4421

Published Sep 14, 2012

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass i…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5106

Published Sep 14, 2012

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended ac…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2109

Published Sep 4, 2012

SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page paramete…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5128

Published Aug 29, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the Adminimize plugin before 1.7.22 for WordPress allow remote attackers to inject arbitrary web script or HTML via the page…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4926

Published Aug 29, 2012

Cross-site scripting (XSS) vulnerability in adminimize/adminimize_page.php in the Adminimize plugin before 1.7.22 for WordPress allows remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 627 CVEsPage 14 of 26