Skip to main content

Vendor archive

wordpress CVEs

Beta · best-effort

627 CVEs tagged to vendor wordpress36 Critical, 136 High, 429 Medium, 26 Low, 0 Unrated.

CVE-2011-3854

Published Sep 28, 2011

Cross-site scripting (XSS) vulnerability in the ZenLite theme before 4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3853

Published Sep 28, 2011

Cross-site scripting (XSS) vulnerability in the Hybrid theme before 0.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3852

Published Sep 28, 2011

Cross-site scripting (XSS) vulnerability in the EvoLve theme before 1.2.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3851

Published Sep 28, 2011

Cross-site scripting (XSS) vulnerability in the News theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3850

Published Sep 28, 2011

Cross-site scripting (XSS) vulnerability in the Atahualpa theme before 3.6.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3818

Published Sep 24, 2011

WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4825

Published Aug 24, 2011

Cross-site scripting (XSS) vulnerability in magpie_debug.php in the Twitter Feed plugin (wp-twitter-feed) 0.3.1 for WordPress allows remote attackers to inject arbitrary web scrip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3130

Published Aug 10, 2011

wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3129

Published Aug 10, 2011

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3128

Published Aug 10, 2011

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3127

Published Aug 10, 2011

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier f…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3126

Published Aug 10, 2011

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3125

Published Aug 10, 2011

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hardening."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3122

Published Aug 10, 2011

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4779

Published Apr 7, 2011

Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for WordPress allows remote attackers to inject arbitrary web scrip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0701

Published Mar 14, 2011

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0700

Published Mar 14, 2011

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) th…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 426-450 of 627 CVEsPage 18 of 26