Show filters
77 Total Results
Displaying 21-30 of 77
Sort by:
Attacker Value
Unknown

CVE-2013-2204

Disclosure Date: July 08, 2013 (last updated October 05, 2023)
moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.
0
Attacker Value
Unknown

CVE-2013-2205

Disclosure Date: July 08, 2013 (last updated October 05, 2023)
The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.
0
Attacker Value
Unknown

CVE-2012-4422

Disclosure Date: September 14, 2012 (last updated October 05, 2023)
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.
0
Attacker Value
Unknown

CVE-2010-5106

Disclosure Date: September 14, 2012 (last updated October 05, 2023)
The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.
0
Attacker Value
Unknown

CVE-2012-4421

Disclosure Date: September 14, 2012 (last updated October 05, 2023)
The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.
0
Attacker Value
Unknown

CVE-2012-3384

Disclosure Date: July 22, 2012 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown

CVE-2012-3385

Disclosure Date: July 22, 2012 (last updated October 04, 2023)
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.
0
Attacker Value
Unknown

CVE-2011-4957

Disclosure Date: June 27, 2012 (last updated October 04, 2023)
The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE library, which allows remote attackers to cause a denial of service (crash) via a comment with a crafted URL that triggers many recursive calls.
0
Attacker Value
Unknown

CVE-2011-4956

Disclosure Date: June 27, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-1936

Disclosure Date: May 03, 2012 (last updated November 08, 2023)
The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user account instead of a user session, which might make it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks on specific actions and objects by sniffing the network, as demonstrated by attacks against the wp-admin/admin-ajax.php and wp-admin/user-new.php scripts. NOTE: the vendor reportedly disputes the significance of this issue because wp_create_nonce operates as intended, even if it is arguably inconsistent with certain CSRF protection details advocated by external organizations
0