Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2017-14719
Disclosure Date: September 23, 2017 (last updated November 26, 2024)
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
0
Attacker Value
Unknown
CVE-2014-9031
Disclosure Date: November 25, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.
0
Attacker Value
Unknown
CVE-2014-9034
Disclosure Date: November 25, 2014 (last updated October 05, 2023)
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.
0
Attacker Value
Unknown
CVE-2014-9037
Disclosure Date: November 25, 2014 (last updated October 05, 2023)
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.
0
Attacker Value
Unknown
CVE-2014-9038
Disclosure Date: November 25, 2014 (last updated October 05, 2023)
wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.
0
Attacker Value
Unknown
CVE-2014-9039
Disclosure Date: November 25, 2014 (last updated October 05, 2023)
wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.
0
Attacker Value
Unknown
CVE-2014-9036
Disclosure Date: November 25, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.
0
Attacker Value
Unknown
CVE-2014-9035
Disclosure Date: November 25, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0