Skip to main content

Vendor archive

wordpress CVEs

Beta · best-effort

627 CVEs tagged to vendor wordpress36 Critical, 136 High, 429 Medium, 26 Low, 0 Unrated.

CVE-2012-3574

Published Jun 16, 2012

Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6 for WordPress allows remote attackers to execute arbitrary…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2633

Published Jun 15, 2012

Cross-site scripting (XSS) vulnerability in wassup.php in the WassUp plugin before 1.8.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Use…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2920

Published May 21, 2012

Cross-site scripting (XSS) vulnerability in the userphoto_options_page function in user-photo.php in the User Photo plugin before 0.9.5.2 for WordPress allows remote attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1936

Published May 3, 2012

The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user account instead of a user session, which might make it easi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2404

Published Apr 21, 2012

wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2403

Published Apr 21, 2012

wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2402

Published Apr 21, 2012

wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspe…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2401

Published Apr 21, 2012

Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2400

Published Apr 21, 2012

Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-2399

Published Apr 21, 2012

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other pro…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-5082

Published Mar 19, 2012

Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1205

Published Feb 24, 2012

PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute arbitrary PHP code via a URL…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1068

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1067

Published Feb 14, 2012

SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content act…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0937

Published Jan 30, 2012

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which al…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0782

Published Jan 30, 2012

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 627 CVEsPage 16 of 26