Skip to main content

Vendor archive

wordpress CVEs

Beta · best-effort

627 CVEs tagged to vendor wordpress36 Critical, 136 High, 429 Medium, 26 Low, 0 Unrated.

CVE-2011-4899

Published Jan 30, 2012

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4898

Published Jan 30, 2012

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whet…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0898

Published Jan 20, 2012

Directory traversal vulnerability in meb_download.php in the myEASYbackup plugin 1.0.8.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dw…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5051

Published Jan 4, 2012

Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file wit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4673

Published Dec 2, 2011

SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3864

Published Sep 28, 2011

Cross-site scripting (XSS) vulnerability in the The Erudite theme before 2.7.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3862

Published Sep 28, 2011

Cross-site scripting (XSS) vulnerability in the Morning Coffee theme before 3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3860

Published Sep 28, 2011

Cross-site scripting (XSS) vulnerability in the Cover WP theme before 1.6.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3859

Published Sep 28, 2011

Cross-site scripting (XSS) vulnerability in the Trending theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3858

Published Sep 28, 2011

Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 627 CVEsPage 17 of 26