Show filters
472 Total Results
Displaying 211-220 of 472
Sort by:
Attacker Value
Unknown
CVE-2015-5715
Disclosure Date: May 22, 2016 (last updated November 25, 2024)
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-1564
Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.
0
Attacker Value
Unknown
CVE-2016-2222
Disclosure Date: May 22, 2016 (last updated November 25, 2024)
The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.
0
Attacker Value
Unknown
CVE-2015-8834
Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3440.
0
Attacker Value
Unknown
CVE-2015-5714
Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.
0
Attacker Value
Unknown
CVE-2015-5734
Disclosure Date: November 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.
0
Attacker Value
Unknown
CVE-2015-5733
Disclosure Date: November 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.
0
Attacker Value
Unknown
CVE-2015-5732
Disclosure Date: November 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.
0
Attacker Value
Unknown
CVE-2015-2213
Disclosure Date: November 09, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.
0
Attacker Value
Unknown
CVE-2015-5731
Disclosure Date: November 09, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.
0