Show filters
472 Total Results
Displaying 201-210 of 472
Sort by:
Attacker Value
Unknown

CVE-2016-5837

Disclosure Date: June 29, 2016 (last updated November 25, 2024)
WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-5839

Disclosure Date: June 29, 2016 (last updated November 25, 2024)
WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-5836

Disclosure Date: June 29, 2016 (last updated November 25, 2024)
The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-5834

Disclosure Date: June 29, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.
0
Attacker Value
Unknown

CVE-2016-5838

Disclosure Date: June 29, 2016 (last updated November 25, 2024)
WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.
0
Attacker Value
Unknown

CVE-2016-5832

Disclosure Date: June 29, 2016 (last updated November 25, 2024)
The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-4567

Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."
0
Attacker Value
Unknown

CVE-2016-4566

Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
0
Attacker Value
Unknown

CVE-2016-2221

Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated by an https:example.com URL.
0
Attacker Value
Unknown

CVE-2015-7989

Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.
0