Latest wordpress wordpress Vulnerabilities

WordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure
WordPress WordPress>=4.7<4.7.27
WordPress WordPress>=4.8<4.8.23
WordPress WordPress>=4.9<4.9.24
WordPress WordPress>=5.0<5.0.20
WordPress WordPress>=5.1<5.1.17
WordPress WordPress>=5.2<5.2.19
and 11 more
WordPress < 6.3.2 is vulnerable to Broken Access Control
WordPress WordPress>=4.1<=4.1.38
WordPress WordPress>=4.2<=4.2.35
WordPress WordPress>=4.3<=4.3.31
WordPress WordPress>=4.4<=4.4.30
WordPress WordPress>=4.5<=4.5.29
WordPress WordPress>=4.6<=4.6.26
and 19 more
Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7...
WordPress WordPress>=5.9<=5.9.7
WordPress WordPress>=6.0<=6.0.5
WordPress WordPress>=6.1<=6.1.3
WordPress WordPress>=6.2<=6.2.2
WordPress WordPress>=6.3<=6.3.1
Wordpress Gutenberg<=16.8.0
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation f...
WordPress WordPress<4.1.38
WordPress WordPress>=4.2<4.2.35
WordPress WordPress>=4.3<4.3.31
WordPress WordPress>=4.4<4.4.30
WordPress WordPress>=4.5<4.5.29
WordPress WordPress>=4.6<4.6.26
and 16 more
WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not recei...
WordPress WordPress<=6.1.1
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all...
WordPress WordPress<3.7.40
WordPress WordPress>=3.8<3.8.40
WordPress WordPress>=3.9<3.9.39
WordPress WordPress>=4.0<4.0.37
WordPress WordPress>=4.1<4.1.37
WordPress WordPress>=4.2<4.2.34
and 18 more
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post b...
WordPress WordPress<3.7.40
WordPress WordPress>=3.8<3.8.40
WordPress WordPress>=3.9<3.9.39
WordPress WordPress>=4.0<4.0.37
WordPress WordPress>=4.1<4.1.37
WordPress WordPress>=4.2<4.2.34
and 18 more
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all...
WordPress WordPress<3.7.40
WordPress WordPress>=3.8<3.8.40
WordPress WordPress>=3.9<3.9.39
WordPress WordPress>=4.0<4.0.37
WordPress WordPress>=4.1<4.1.37
WordPress WordPress>=4.2<4.2.34
and 18 more
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post...
WordPress WordPress>=3.1<3.1.2
WordPress WordPress<3.0.6
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for uninten...
debian/wordpress
WordPress WordPress<5.8.3
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Fedoraproject Fedora=34
and 1 more
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening un...
debian/wordpress
WordPress WordPress<5.8.3
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Fedoraproject Fedora=34
and 1 more
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute ...
debian/wordpress
WordPress WordPress<5.8.3
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
WordPress Core WP_Query SQL Injection Information Disclosure Vulnerability
debian/wordpress
WordPress Core
WordPress WordPress<5.8.3
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=9.0
and 2 more
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that ...
WordPress WordPress<5.8
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under ...
debian/wordpress
WordPress WordPress>=5.2<5.8.1
Debian Debian Linux=10.0
Debian Debian Linux=11.0
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view pri...
WordPress WordPress=5.8-beta1
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like con...
debian/wordpress
debian/wordpress<=5.0.12+dfsg1-0+deb10u1<=5.7.1+dfsg1-2
WordPress WordPress>=5.0<5.8
Debian Debian Linux=10.0
Debian Debian Linux=11.0
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has...
WordPress WordPress=5.8-beta1
WordPress WordPress=5.8-beta2
### Impact This is a reintroduction of an earlier issue (CVE-2018-19296) by an unrelated bug fix in PHPMailer 6.1.8. An external file may be unexpectedly executable if it is used as a path to an atta...
composer/phpmailer/phpmailer>=6.1.8<6.4.1
Phpmailer Project Phpmailer>=6.1.8<=6.4.0
WordPress WordPress>=3.7<3.7.36
WordPress WordPress>=3.8<3.8.36
WordPress WordPress>=3.9<3.9.34
WordPress WordPress>=4.0<4.0.33
and 18 more
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. Thi...
debian/wordpress
debian/wordpress<=5.6.1+dfsg1-1<=5.7+dfsg1-1<=5.0.11+dfsg1-0+deb10u1
WordPress WordPress>=4.7<5.7.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installa...
debian/wordpress
WordPress WordPress>=5.6.0<5.7.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
WordPress before 5.5.2 allows stored XSS via post slugs.
debian/wordpress
WordPress WordPress<5.5.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=9.0
and 1 more
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
debian/wordpress
WordPress WordPress<5.5.2
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
and 1 more
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
debian/wordpress
WordPress WordPress<5.5.2
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
and 1 more
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
debian/wordpress
WordPress WordPress<5.5.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=9.0
and 1 more
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
debian/wordpress
WordPress WordPress<5.5.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=10.0
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
debian/wordpress
WordPress WordPress<5.5.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=9.0
and 1 more
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
debian/wordpress
WordPress WordPress<5.5.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=10.0
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, lead...
debian/wordpress
WordPress WordPress<5.5.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=10.0
debian/wordpress
WordPress WordPress<5.5.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=9.0
and 1 more
The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable ...
Elementor Elementor Pro<=3.0.5
WordPress WordPress<=5.5.1
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
WordPress WordPress<5.4.2
In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts...
WordPress WordPress>=3.7<3.7.34
WordPress WordPress>=3.8<3.8.34
WordPress WordPress>=3.9<3.9.32
WordPress WordPress>=4.0<4.0.31
WordPress WordPress>=4.1<4.1.31
WordPress WordPress>=4.2<4.2.28
and 16 more
In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does requir...
debian/wordpress
WordPress WordPress>=3.7<3.7.34
WordPress WordPress>=3.8<3.8.34
WordPress WordPress>=3.9<3.9.32
WordPress WordPress>=4.0<4.0.31
WordPress WordPress>=4.1<4.1.31
and 18 more
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to scr...
debian/wordpress
WordPress WordPress>=3.7<3.7.34
WordPress WordPress>=3.8<3.8.34
WordPress WordPress>=3.9<3.9.32
WordPress WordPress>=4.0<4.0.31
WordPress WordPress>=4.1<4.1.31
and 18 more
In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse...
debian/wordpress
WordPress WordPress>=3.7<3.7.34
WordPress WordPress>=3.8<3.8.34
WordPress WordPress>=3.9<3.9.32
WordPress WordPress>=4.0<4.0.31
WordPress WordPress>=4.1<4.1.31
and 18 more
In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has ...
debian/wordpress
WordPress WordPress>=3.7<3.7.34
WordPress WordPress>=3.8<3.8.34
WordPress WordPress>=3.9<3.9.32
WordPress WordPress>=4.0<4.0.31
WordPress WordPress>=4.1<4.1.31
and 18 more
In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with...
debian/wordpress
WordPress WordPress>=3.7<3.7.33
WordPress WordPress>=3.8<3.8.33
WordPress WordPress>=3.9<3.9.31
WordPress WordPress>=4.0<4.0.30
WordPress WordPress>=4.1<4.1.30
and 16 more
In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ...
debian/wordpress
WordPress WordPress<5.4.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1...
debian/wordpress
WordPress WordPress<5.4.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=8.0
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party...
debian/wordpress
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
WordPress WordPress>=3.7<3.7.33
WordPress WordPress>=3.8<3.8.33
and 16 more
In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5...
debian/wordpress
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
WordPress WordPress>=3.7<3.7.33
WordPress WordPress>=3.8<3.8.33
and 16 more
In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user...
debian/wordpress
WordPress WordPress>=4.7<5.4.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has be...
debian/wordpress
WordPress WordPress>=3.7<5.3.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or ...
debian/wordpress
WordPress WordPress>=3.7<5.3.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript&colon...
debian/wordpress
WordPress WordPress<5.3.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin...
debian/wordpress
WordPress WordPress<5.3.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an ad...
debian/wordpress
WordPress WordPress>3.7<5.3.1
WordPress WordPress=3.7
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/wordpress
WordPress WordPress<5.2.4
Debian Debian Linux=9.0
Debian Debian Linux=10.0
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
debian/wordpress
WordPress WordPress<5.2.4
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203