Show filters
34 Total Results
Displaying 11-20 of 34
Sort by:
Attacker Value
Unknown
CVE-2012-6633
Disclosure Date: January 21, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.
0
Attacker Value
Unknown
CVE-2010-5293
Disclosure Date: January 21, 2014 (last updated October 05, 2023)
wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.
0
Attacker Value
Unknown
CVE-2012-6634
Disclosure Date: January 21, 2014 (last updated October 05, 2023)
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.
0
Attacker Value
Unknown
CVE-2010-5295
Disclosure Date: January 21, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.
0
Attacker Value
Unknown
CVE-2012-3414
Disclosure Date: July 19, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
0
Attacker Value
Unknown
CVE-2012-4422
Disclosure Date: September 14, 2012 (last updated October 05, 2023)
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.
0
Attacker Value
Unknown
CVE-2010-5106
Disclosure Date: September 14, 2012 (last updated October 05, 2023)
The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.
0
Attacker Value
Unknown
CVE-2012-4421
Disclosure Date: September 14, 2012 (last updated October 05, 2023)
The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.
0
Attacker Value
Unknown
CVE-2012-3384
Disclosure Date: July 22, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown
CVE-2012-3385
Disclosure Date: July 22, 2012 (last updated October 04, 2023)
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.
0