Show filters
472 Total Results
Displaying 61-70 of 472
Sort by:
Attacker Value
Unknown
CVE-2022-29427
Disclosure Date: May 04, 2022 (last updated October 07, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress.
0
Attacker Value
Unknown
CVE-2021-25111
Disclosure Date: April 25, 2022 (last updated October 07, 2023)
The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue
0
Attacker Value
Unknown
CVE-2011-1762
Disclosure Date: April 18, 2022 (last updated October 07, 2023)
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
0
Attacker Value
Unknown
CVE-2021-36833
Disclosure Date: March 02, 2022 (last updated October 07, 2023)
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.
0
Attacker Value
Unknown
CVE-2021-25055
Disclosure Date: February 21, 2022 (last updated October 07, 2023)
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
0
Attacker Value
Unknown
CVE-2022-21664
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 4.1.34. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-21663
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-21662
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-21661
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2021-44223
Disclosure Date: November 25, 2021 (last updated February 23, 2025)
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.
0