Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2014-8585

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.
0
Attacker Value
Unknown

CVE-2013-2705

Disclosure Date: May 13, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings.
0
Attacker Value
Unknown

CVE-2013-0237

Disclosure Date: July 08, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
0
Attacker Value
Unknown

CVE-2012-6527

Disclosure Date: January 31, 2013 (last updated December 27, 2023)
Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
0
Attacker Value
Unknown

CVE-2012-2401

Disclosure Date: April 21, 2012 (last updated October 04, 2023)
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.
0
Attacker Value
Unknown

CVE-2009-2334

Disclosure Date: July 10, 2009 (last updated October 04, 2023)
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.
0
Attacker Value
Unknown

CVE-2009-2432

Disclosure Date: July 10, 2009 (last updated October 04, 2023)
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2008-5278

Disclosure Date: November 28, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
0
Attacker Value
Unknown

CVE-2008-4769

Disclosure Date: October 28, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-3233

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0