Skip to main content

Vendor archive

wordpress CVEs

Beta · best-effort

627 CVEs tagged to vendor wordpress36 Critical, 136 High, 429 Medium, 26 Low, 0 Unrated.

CVE-2014-3844

Published May 22, 2014

The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings via unspecified vectors. NOT…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0166

Published Apr 10, 2014

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cooki…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-0165

Published Apr 10, 2014

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-a…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-4920

Published Apr 4, 2014

Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugin before 1.4.4 for WordPress allows remote attackers to rea…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0735

Published Apr 2, 2014

Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-0734

Published Mar 28, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1409

Published Mar 3, 2014

Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1888

Published Mar 1, 2014

Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6635

Published Jan 21, 2014

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensiti…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6634

Published Jan 21, 2014

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6633

Published Jan 21, 2014

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editabl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5270

Published Jan 21, 2014

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5297

Published Jan 21, 2014

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authentica…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-5296

Published Jan 21, 2014

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5295

Published Jan 21, 2014

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's autho…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5294

Published Jan 21, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 627 CVEsPage 9 of 26