Show filters
472 Total Results
Displaying 151-160 of 472
Sort by:
Attacker Value
Unknown

CVE-2017-17093

Disclosure Date: December 02, 2017 (last updated November 26, 2024)
wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.
0
Attacker Value
Unknown

CVE-2017-16510

Disclosure Date: November 02, 2017 (last updated November 26, 2024)
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
0
Attacker Value
Unknown

CVE-2012-6707

Disclosure Date: October 19, 2017 (last updated November 26, 2024)
WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.
0
Attacker Value
Unknown

CVE-2016-9263

Disclosure Date: October 12, 2017 (last updated November 26, 2024)
WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.
0
Attacker Value
Unknown

CVE-2017-14990

Disclosure Date: October 03, 2017 (last updated November 26, 2024)
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).
0
Attacker Value
Unknown

CVE-2017-14722

Disclosure Date: September 23, 2017 (last updated November 26, 2024)
Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.
0
Attacker Value
Unknown

CVE-2017-14726

Disclosure Date: September 23, 2017 (last updated November 26, 2024)
Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.
0
Attacker Value
Unknown

CVE-2017-14719

Disclosure Date: September 23, 2017 (last updated November 26, 2024)
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
0
Attacker Value
Unknown

CVE-2017-14718

Disclosure Date: September 23, 2017 (last updated November 26, 2024)
Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.
0
Attacker Value
Unknown

CVE-2017-14725

Disclosure Date: September 23, 2017 (last updated November 26, 2024)
Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
0