Skip to content
Noroxi

WordPress records

665 published records for vendor wordpress.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

665 records
  • The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    phpmailer project · phpmailerDec 30, 2016

  • CVE-2026-63030
    72This week

    WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

    CriticalCVSS 9.8KEVWeaponizedEPSS 10%

    wordpress · wordpressJul 17, 2026

  • CVE-2016-10045
    68This week

    The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently e

    CriticalCVSS 9.8WeaponizedEPSS 98%

    phpmailer project · phpmailerDec 30, 2016

  • CVE-2026-87902
    68This week

    An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the

    HighCVSS 8.1KEVWeaponizedEPSS 20%

    wordpress · wordpressSep 22, 2026

  • CVE-2019-8942
    60This week

    WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an a

    HighCVSS 8.8WeaponizedEPSS 83%

    wordpress · wordpressFeb 19, 2019

  • SQL injection in WordPress

    HighCVSS 7.5Proof of conceptEPSS 98%

    wordpress · wordpressJan 6, 2022

  • The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before

    HighCVSS 7.5WeaponizedEPSS 85%

    wordpress · wordpressApr 2, 2017

  • WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

    MediumCVSS 5.9KEVWeaponizedEPSS 6%

    wordpress · wordpressJul 17, 2026

  • WordPress through 5.0.3 allows Path Traversal in wp_crop_image().

    MediumCVSS 6.5WeaponizedEPSS 93%

    wordpress · wordpressFeb 19, 2019

  • WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb param

    HighCVSS 8.8WeaponizedEPSS 62%

    wordpress · wordpressJun 26, 2018

  • WordPress Authenticated XXE attack when installation is running PHP 8

    MediumCVSS 6.5Proof of conceptEPSS 86%

    wordpress · wordpressApr 15, 2021

  • In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of regist

    HighCVSS 7.5Proof of conceptEPSS 73%

    wordpress · wordpressFeb 6, 2018

  • WordPress before 5.8 lacks support for the Update URI plugin header.

    CriticalCVSS 9.8No exploitEPSS 29%

    wordpress · wordpressNov 25, 2021

  • wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not prop

    MediumCVSS 5.3Proof of conceptEPSS 87%

    wordpress · wordpressJan 14, 2017

  • WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default conf

    HighCVSS 8.8Proof of conceptEPSS 39%

    wordpress · wordpressMar 14, 2019

  • In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMedi

    CriticalCVSS 9.8Proof of conceptEPSS 27%

    wordpress · wordpressDec 14, 2018

  • WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists,

    MediumCVSS 5.0WeaponizedEPSS 85%

    wordpress · wordpressJul 10, 2009

  • Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to ex

    CriticalCVSS 10.0Proof of conceptEPSS 18%

    wordpress · wordpressJun 15, 2012

  • wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers

    MediumCVSS 5.0Proof of conceptEPSS 83%

    wordpress · wordpressNov 25, 2014

  • WordPress Core < 6.2.1 - Directory Traversal

    MediumCVSS 5.4Proof of conceptEPSS 80%

    wordpress · wordpressMay 17, 2023

  • WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due t

    MediumCVSS 6.1Proof of conceptEPSS 71%

    wordpress · wordpressMay 3, 2024

  • Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attacke

    CriticalCVSS 10.0Proof of conceptEPSS 17%

    giulio ganci · wp downloads managerJul 30, 2008

  • Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitr

    CriticalCVSS 10.0Proof of conceptEPSS 15%

    rbx gallery · rbx galleryJun 15, 2012

  • PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote a

    HighCVSS 7.5Proof of conceptEPSS 48%

    wordpress · sniplets pluginFeb 28, 2008

  • WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

    CriticalCVSS 9.8Proof of conceptEPSS 16%

    wordpress · wordpressNov 2, 2020