Search

Found 370 results in 122ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-17094 medium 5.4 5.4 FIX debian debian wordpress 9y ago wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.
CVE-2017-17093 medium 5.4 5.4 FIX debian debian wordpress 9y ago wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language settin…
CVE-2017-17092 medium 5.4 5.4 FIX debian debian wordpress 9y ago wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted fi…
CVE-2017-17091 high 8.8 8.8 FIX debian debian wordpress 9y ago wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restriction…
CVE-2017-16510 critical 9.8 9.8 FIX debian debian wordpress 9y ago WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "d…
CVE-2012-6707 high 7.5 7.5 FIX debian debian wordpress 9y ago WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach…
CVE-2016-9263 medium 4.7 4.7 FIX debian debian wordpress 9y ago WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained wit…
CVE-2017-14990 medium 6.5 6.5 FIX debian debian wordpress 9y ago WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack u…
CVE-2017-14726 medium 6.1 6.1 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.
CVE-2017-14725 medium 5.4 5.4 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
CVE-2017-14724 medium 6.1 6.1 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.
CVE-2017-14723 critical 9.8 9.8 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injec…
CVE-2017-14722 high 7.5 7.5 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.
CVE-2017-14721 medium 6.1 6.1 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.
CVE-2017-14720 medium 6.1 6.1 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.
CVE-2017-14719 high 7.5 7.5 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
CVE-2017-14718 medium 6.1 6.1 FIX debian debian wordpress 9y ago Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.
CVE-2017-9066 high 8.6 8.6 FIX debian debian wordpress 9y ago In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
CVE-2017-9065 high 7.5 7.5 FIX debian debian wordpress 9y ago In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.
CVE-2017-9064 high 8.8 8.8 FIX debian debian wordpress 9y ago In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.
CVE-2017-9063 medium 6.1 6.1 FIX debian debian wordpress 9y ago In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.
CVE-2017-9062 high 8.6 8.6 FIX debian debian wordpress 9y ago In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
CVE-2017-9061 medium 6.1 6.1 FIX debian debian wordpress 9y ago In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filen…
CVE-2017-8295 medium 5.9 6.9 EXPFIX debian debian wordpress 9y ago WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?ac…
CVE-2017-1001000 high 7.5 8.5 EXPFIX debian debian wordpress 9y ago The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows …
CVE-2017-6819 medium 6.5 6.5 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an …
CVE-2017-6818 medium 6.1 6.1 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
CVE-2017-6817 medium 5.4 5.4 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
CVE-2017-6816 medium 4.9 4.9 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
CVE-2017-6815 medium 6.1 6.1 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.
CVE-2017-6814 medium 5.4 5.4 FIX arch archdebian debian wordpress 9y ago In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortco…
CVE-2017-5612 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or…
CVE-2017-5611 critical 9.8 9.8 FIX debian debian wordpressoracle 10y ago SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected…
CVE-2017-5610 medium 5.3 5.3 FIX debian debian wordpress 10y ago wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypas…
CVE-2016-6897 medium 6.5 7.5 EXPFIX debian debian wordpress 10y ago Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authenticatio…
CVE-2016-6896 high 7.1 8.1 EXPFIX debian debian wordpress 10y ago Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read…
CVE-2016-10148 medium 4.3 4.3 FIX debian debian wordpress 10y ago The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authen…
CVE-2017-5493 high 7.5 7.5 FIX arch archdebian debian wordpress 10y ago wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended a…
CVE-2017-5492 high 8.8 8.8 FIX arch archdebian debian wordpress 10y ago Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims …
CVE-2017-5491 medium 5.3 5.3 FIX arch archdebian debian wordpress 10y ago wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
CVE-2017-5490 medium 6.1 6.1 FIX arch archdebian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or…
CVE-2017-5489 high 8.8 8.8 FIX arch archdebian debian wordpress 10y ago Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.
CVE-2017-5488 medium 6.1 6.1 FIX arch archdebian debian wordpress 10y ago Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version…
CVE-2017-5487 medium 5.3 6.3 EXPFIX arch archdebian debian wordpress 10y ago wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote…
CVE-2016-7169 medium 6.3 6.3 FIX arch archdebian debian wordpress 10y ago Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authent…
CVE-2016-7168 medium 4.8 4.8 FIX arch archdebian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HT…
CVE-2016-10045 critical 9.8 10.0 EXPFIX arch archdebian debian phpmailer_projectwordpressjoomla 10y ago Remote code execution in PHPMailer
CVE-2016-6635 high 8.8 8.8 FIX debian debian wordpress 10y ago Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authent…
CVE-2016-6634 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-4029 high 8.6 8.6 FIX debian debian wordpress 10y ago WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via…
CVE-2016-5839 high 7.5 7.5 FIX debian debian wordpress 10y ago WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.
CVE-2016-5838 high 7.5 7.5 FIX debian debian wordpress 10y ago WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.
CVE-2016-5837 high 7.5 7.5 FIX debian debian wordpress 10y ago WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.
CVE-2016-5836 high 7.5 7.5 FIX debian debian wordpress 10y ago The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.
CVE-2016-5835 high 7.5 7.5 FIX debian debian wordpress 10y ago WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/re…
CVE-2016-5834 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HT…
CVE-2016-5833 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web scri…
CVE-2016-5832 high 7.5 7.5 FIX debian debian wordpress 10y ago The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.
CVE-2016-4567 medium 6.1 6.1 debian debian mediaelementjswordpress 10y ago MediaElement Vulnerable to Reflected XSS
CVE-2016-4566 medium 6.1 6.1 FIX debian debian wordpressplupload 10y ago Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-O…
CVE-2016-2222 high 8.6 8.6 FIX debian debian wordpress 10y ago The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet o…
CVE-2016-2221 high 7.4 7.4 FIX debian debian wordpress 10y ago Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct ph…
CVE-2016-1564 medium 6.1 6.1 FIX debian debian wordpress 10y ago Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name…
CVE-2015-8834 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored…
CVE-2015-7989 medium 5.4 5.4 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a diff…
CVE-2015-5715 medium 4.3 4.3 FIX debian debian wordpress 10y ago The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arra…
CVE-2015-5714 medium 6.1 6.1 FIX debian debian wordpress 10y ago Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during proces…
CVE-2015-5734 medium 4.3 FIX debian debian wordpress 11y ago Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML v…
CVE-2015-5733 medium 4.3 FIX debian debian wordpress 11y ago Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script…
CVE-2015-5732 medium 4.3 FIX debian debian wordpress 11y ago Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary …
CVE-2015-5731 medium 6.8 FIX debian debian wordpress 11y ago Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, an…
CVE-2015-5730 medium 5.0 FIX debian debian wordpress 11y ago The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to con…
CVE-2015-2213 high 7.5 FIX debian debian wordpress 11y ago SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is …
CVE-2015-3439 medium 4.3 FIX debian debian wordpress 11y ago Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, all…
CVE-2015-3438 medium 4.3 FIX debian debian wordpress 11y ago Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byt…
CVE-2015-5623 medium 4.0 FIX debian debian wordpress 11y ago WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscribe…
CVE-2015-5622 low 3.5 FIX debian debian wordpress 11y ago Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a cra…
CVE-2015-3440 medium 5.3 EXPFIX debian debian wordpress 11y ago Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored…
CVE-2015-3429 medium 4.3 FIX debian debian automatticwordpress 11y ago Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment i…
CVE-2014-9039 medium 4.3 FIX debian debian wordpress 12y ago wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that rec…
CVE-2014-9038 medium 6.4 FIX debian debian wordpress 12y ago wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring…
CVE-2014-9037 medium 6.8 FIX debian debian wordpress 12y ago WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic …
CVE-2014-9036 medium 4.3 FIX debian debian wordpress 12y ago Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a c…
CVE-2014-9035 medium 4.3 FIX debian debian wordpress 12y ago Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script o…
CVE-2014-9034 medium 6.0 EXPFIX debian debian wordpress 12y ago wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long …
CVE-2014-9033 medium 6.8 FIX debian debian wordpress 12y ago Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that res…
CVE-2014-9032 medium 4.3 FIX debian debian wordpress 12y ago Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via …
CVE-2014-9031 medium 4.3 FIX debian debian wordpress 12y ago Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HT…
CVE-2003-1599 high 7.5 wordpress 12y ago PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable.
CVE-2003-1598 high 7.5 FIX debian debian wordpress 12y ago SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.
CVE-2014-5266 medium 6.0 EXPFIX debian debian wordpressdrupal 12y ago The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote atta…
CVE-2014-5265 medium 5.0 FIX debian debian drupalwordpress 12y ago The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion,…
CVE-2014-5240 low 2.1 FIX debian debian wordpress 12y ago Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script o…
CVE-2014-5205 medium 6.8 FIX debian debian wordpress 12y ago wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a…
CVE-2014-5204 medium 6.8 FIX debian debian wordpress 12y ago wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote atta…
CVE-2014-5203 high 7.5 FIX debian debian wordpress 12y ago wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.
CVE-2014-4534 medium 4.3 html5_video_player_with_playlist_plugin_projectwordpress 12y ago Multiple cross-site scripting (XSS) vulnerabilities in videoplayer/autoplay.php in the HTML5 Video Player with Playlist plugin 2.4.0 and earlier for WordPress allow remote attackers to inject arbitra…
CVE-2014-4603 medium 4.3 yahoo\!_updates_for_wordpress_plugin_projectwordpress 12y ago Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web…
CVE-2014-4600 medium 4.3 wp_ultimate_email_marketer_projectwordpress 12y ago Multiple cross-site scripting (XSS) vulnerabilities in contact/edit.php in the WP Ultimate Email Marketer plugin 1.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script …
CVE-2014-4529 medium 4.3 flash_photo_gallery_projectwordpress 12y ago Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path…