Show filters
472 Total Results
Displaying 221-230 of 472
Sort by:
Attacker Value
Unknown

CVE-2015-5730

Disclosure Date: November 09, 2015 (last updated October 05, 2023)
The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.
0
Attacker Value
Unknown

CVE-2015-3439

Disclosure Date: August 05, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.
0
Attacker Value
Unknown

CVE-2015-3438

Disclosure Date: August 05, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.
0
Attacker Value
Unknown

CVE-2015-5623

Disclosure Date: August 03, 2015 (last updated October 05, 2023)
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.
0
Attacker Value
Unknown

CVE-2015-3440

Disclosure Date: August 03, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.
0
Attacker Value
Unknown

CVE-2015-5622

Disclosure Date: August 03, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.
0
Attacker Value
Unknown

CVE-2015-4018

Disclosure Date: May 21, 2015 (last updated October 05, 2023)
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the link_ids[] parameter in an Update action in the syndication.php page to wp-admin/admin.php.
0
Attacker Value
Unknown

CVE-2014-9337

Disclosure Date: December 19, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mikiurl Wordpress Eklentisi plugin 2.0 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) twitter_kullanici or (2) twitter_sifre parameter in a kaydet action in the mikiurl.php page to wp-admin/options-general.php.
0
Attacker Value
Unknown

CVE-2014-9031

Disclosure Date: November 25, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.
0
Attacker Value
Unknown

CVE-2014-9032

Disclosure Date: November 25, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0