Show filters
472 Total Results
Displaying 211-220 of 472
Sort by:
Attacker Value
Unknown

CVE-2015-5715

Disclosure Date: May 22, 2016 (last updated November 25, 2024)
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-1564

Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.
0
Attacker Value
Unknown

CVE-2016-2222

Disclosure Date: May 22, 2016 (last updated November 25, 2024)
The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.
0
Attacker Value
Unknown

CVE-2015-8834

Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3440.
0
Attacker Value
Unknown

CVE-2015-5714

Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.
0
Attacker Value
Unknown

CVE-2015-5734

Disclosure Date: November 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.
0
Attacker Value
Unknown

CVE-2015-5733

Disclosure Date: November 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.
0
Attacker Value
Unknown

CVE-2015-5732

Disclosure Date: November 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.
0
Attacker Value
Unknown

CVE-2015-2213

Disclosure Date: November 09, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.
0
Attacker Value
Unknown

CVE-2015-5731

Disclosure Date: November 09, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.
0