Записи WordPress
665 опубликованных записей вендора wordpress.
Профиль для исследователя
- Попали в KEV
- 4 · 0,6 %
- С эксплойтом
- 15 · 2,3 %
- Pre-auth RCE
- 101
- С записью об исправлении
- 53,2 %
- Медиана: публикация → KEV
- 4 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')235
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')58
- CWE-352 Cross-Site Request Forgery (CSRF)53
- CWE-264 Permissions, Privileges, and Access Controls41
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor30
- CWE-20 Improper Input Validation24
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
665 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2016-10033Готовый эксплойт | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail cphpmailer project · phpmailer · CWE-88 | Критическая9,8 | KEV | 99,7 % | 30 дек. 2016 г. |
72На этой неделе | CVE-2026-63030Готовый эксплойт | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Executionwordpress · wordpress · CWE-436 | Критическая9,8 | KEV | 10,1 % | 17 июл. 2026 г. |
68На этой неделе | CVE-2016-10045Готовый эксплойт | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently ephpmailer project · phpmailer · CWE-77 | Критическая9,8 | — | 97,7 % | 30 дек. 2016 г. |
68На этой неделе | CVE-2026-87902Готовый эксплойт | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the wordpress · wordpress · CWE-98 | Высокая8,1 | KEV | 19,8 % | 22 сент. 2026 г. |
60На этой неделе | CVE-2019-8942Готовый эксплойт | WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an awordpress · wordpress · CWE-434 | Высокая8,8 | — | 82,7 % | 19 февр. 2019 г. |
59В плане | CVE-2022-21661Proof of concept | SQL injection in WordPresswordpress · wordpress · CWE-89 | Высокая7,5 | — | 97,8 % | 6 янв. 2022 г. |
55В плане | CVE-2017-1001000Готовый эксплойт | The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before wordpress · wordpress | Высокая7,5 | — | 84,9 % | 2 апр. 2017 г. |
55В плане | CVE-2026-60137Готовый эксплойт | WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Querywordpress · wordpress · CWE-89 | Средняя5,9 | KEV | 5,9 % | 17 июл. 2026 г. |
54В плане | CVE-2019-8943Готовый эксплойт | WordPress through 5.0.3 allows Path Traversal in wp_crop_image().wordpress · wordpress · CWE-22 | Средняя6,5 | — | 92,6 % | 19 февр. 2019 г. |
54В плане | CVE-2018-12895Готовый эксплойт | WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb paramwordpress · wordpress · CWE-22 | Высокая8,8 | — | 62,2 % | 26 июн. 2018 г. |
52В плане | CVE-2021-29447Proof of concept | WordPress Authenticated XXE attack when installation is running PHP 8wordpress · wordpress · CWE-611 | Средняя6,5 | — | 85,7 % | 15 апр. 2021 г. |
52В плане | CVE-2018-6389Proof of concept | In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registwordpress · wordpress · CWE-400 | Высокая7,5 | — | 72,7 % | 6 февр. 2018 г. |
48В плане | CVE-2021-44223Эксплойта нет | WordPress before 5.8 lacks support for the Update URI plugin header.wordpress · wordpress | Критическая9,8 | — | 29,0 % | 25 нояб. 2021 г. |
47В плане | CVE-2017-5487Proof of concept | wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not propwordpress · wordpress · CWE-200 | Средняя5,3 | — | 87,3 % | 14 янв. 2017 г. |
47В плане | CVE-2019-9787Proof of concept | WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default confwordpress · wordpress · CWE-352 | Высокая8,8 | — | 38,7 % | 14 мар. 2019 г. |
47В плане | CVE-2018-20148Proof of concept | In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediwordpress · wordpress · CWE-502 | Критическая9,8 | — | 26,8 % | 14 дек. 2018 г. |
46В плане | CVE-2009-2335Готовый эксплойт | WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, wordpress · wordpress · CWE-16 | Средняя5,0 | — | 85,0 % | 10 июл. 2009 г. |
46В плане | CVE-2012-3576Proof of concept | Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to exwordpress · wordpress · CWE-264 | Критическая10,0 | — | 18,4 % | 15 июн. 2012 г. |
45В плане | CVE-2014-9034Proof of concept | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackerswordpress · wordpress · CWE-19 | Средняя5,0 | — | 82,7 % | 25 нояб. 2014 г. |
45В плане | CVE-2023-2745Proof of concept | WordPress Core < 6.2.1 - Directory Traversalwordpress · wordpress · CWE-22 | Средняя5,4 | — | 79,5 % | 17 мая 2023 г. |
45В плане | CVE-2024-4439Proof of concept | WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due twordpress · wordpress · CWE-80 | Средняя6,1 | — | 71,0 % | 3 мая 2024 г. |
45В плане | CVE-2008-3362Proof of concept | Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackegiulio ganci · wp downloads manager · CWE-20 | Критическая10,0 | — | 16,8 % | 30 июл. 2008 г. |
45В плане | CVE-2012-3575Proof of concept | Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrrbx gallery · rbx gallery · CWE-264 | Критическая10,0 | — | 15,4 % | 15 июн. 2012 г. |
44В плане | CVE-2008-1059Proof of concept | PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote awordpress · sniplets plugin · CWE-94 | Высокая7,5 | — | 48,3 % | 28 февр. 2008 г. |
44В плане | CVE-2020-28032Proof of concept | WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.wordpress · wordpress · CWE-502 | Критическая9,8 | — | 16,1 % | 2 нояб. 2020 г. |
- CVE-2016-1003399Срочно
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail c
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %phpmailer project · phpmailer30 дек. 2016 г.
- CVE-2026-6303072На этой неделе
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 10 %wordpress · wordpress17 июл. 2026 г.
- CVE-2016-1004568На этой неделе
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently e
КритическаяCVSS 9,8Готовый эксплойтEPSS 98 %phpmailer project · phpmailer30 дек. 2016 г.
- CVE-2026-8790268На этой неделе
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 20 %wordpress · wordpress22 сент. 2026 г.
- CVE-2019-894260На этой неделе
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an a
ВысокаяCVSS 8,8Готовый эксплойтEPSS 83 %wordpress · wordpress19 февр. 2019 г.
- CVE-2022-2166159В плане
SQL injection in WordPress
ВысокаяCVSS 7,5Proof of conceptEPSS 98 %wordpress · wordpress6 янв. 2022 г.
- CVE-2017-100100055В плане
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before
ВысокаяCVSS 7,5Готовый эксплойтEPSS 85 %wordpress · wordpress2 апр. 2017 г.
- CVE-2026-6013755В плане
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
СредняяCVSS 5,9KEVГотовый эксплойтEPSS 6 %wordpress · wordpress17 июл. 2026 г.
- CVE-2019-894354В плане
WordPress through 5.0.3 allows Path Traversal in wp_crop_image().
СредняяCVSS 6,5Готовый эксплойтEPSS 93 %wordpress · wordpress19 февр. 2019 г.
- CVE-2018-1289554В плане
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb param
ВысокаяCVSS 8,8Готовый эксплойтEPSS 62 %wordpress · wordpress26 июн. 2018 г.
- CVE-2021-2944752В плане
WordPress Authenticated XXE attack when installation is running PHP 8
СредняяCVSS 6,5Proof of conceptEPSS 86 %wordpress · wordpress15 апр. 2021 г.
- CVE-2018-638952В плане
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of regist
ВысокаяCVSS 7,5Proof of conceptEPSS 73 %wordpress · wordpress6 февр. 2018 г.
- CVE-2021-4422348В плане
WordPress before 5.8 lacks support for the Update URI plugin header.
КритическаяCVSS 9,8Эксплойта нетEPSS 29 %wordpress · wordpress25 нояб. 2021 г.
- CVE-2017-548747В плане
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not prop
СредняяCVSS 5,3Proof of conceptEPSS 87 %wordpress · wordpress14 янв. 2017 г.
- CVE-2019-978747В плане
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default conf
ВысокаяCVSS 8,8Proof of conceptEPSS 39 %wordpress · wordpress14 мар. 2019 г.
- CVE-2018-2014847В плане
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMedi
КритическаяCVSS 9,8Proof of conceptEPSS 27 %wordpress · wordpress14 дек. 2018 г.
- CVE-2009-233546В плане
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists,
СредняяCVSS 5,0Готовый эксплойтEPSS 85 %wordpress · wordpress10 июл. 2009 г.
- CVE-2012-357646В плане
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to ex
КритическаяCVSS 10,0Proof of conceptEPSS 18 %wordpress · wordpress15 июн. 2012 г.
- CVE-2014-903445В плане
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers
СредняяCVSS 5,0Proof of conceptEPSS 83 %wordpress · wordpress25 нояб. 2014 г.
- CVE-2023-274545В плане
WordPress Core < 6.2.1 - Directory Traversal
СредняяCVSS 5,4Proof of conceptEPSS 80 %wordpress · wordpress17 мая 2023 г.
- CVE-2024-443945В плане
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due t
СредняяCVSS 6,1Proof of conceptEPSS 71 %wordpress · wordpress3 мая 2024 г.
- CVE-2008-336245В плане
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attacke
КритическаяCVSS 10,0Proof of conceptEPSS 17 %giulio ganci · wp downloads manager30 июл. 2008 г.
- CVE-2012-357545В плане
Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitr
КритическаяCVSS 10,0Proof of conceptEPSS 15 %rbx gallery · rbx gallery15 июн. 2012 г.
- CVE-2008-105944В плане
PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote a
ВысокаяCVSS 7,5Proof of conceptEPSS 48 %wordpress · sniplets plugin28 февр. 2008 г.
- CVE-2020-2803244В плане
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
КритическаяCVSS 9,8Proof of conceptEPSS 16 %wordpress · wordpress2 нояб. 2020 г.