Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2017-14722
Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.305
EPSS Ranking
96.5%
CVSS Severity
CVSS v3 Score
7.5
CVSS v2 Score
5.0
References
http://www.securityfocus.com/bid/100912
http://www.securitytracker.com/id/1039553
https://core.trac.wordpress.org/changeset/41397
https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
https://wpvulndb.com/vulnerabilities/8912
https://www.debian.org/security/2017/dsa-3997
http://www.securityfocus.com/bid/100912
http://www.securitytracker.com/id/1039553
https://core.trac.wordpress.org/changeset/41397
https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
https://wpvulndb.com/vulnerabilities/8912
https://www.debian.org/security/2017/dsa-3997
Products affected by CVE-2017-14722
Wordpress
»
Wordpress
»
Version:
4.7
cpe:2.3:a:wordpress:wordpress:4.7
Wordpress
»
Wordpress
»
Version:
4.7.1
cpe:2.3:a:wordpress:wordpress:4.7.1
Wordpress
»
Wordpress
»
Version:
4.7.2
cpe:2.3:a:wordpress:wordpress:4.7.2
Wordpress
»
Wordpress
»
Version:
4.7.3
cpe:2.3:a:wordpress:wordpress:4.7.3
Wordpress
»
Wordpress
»
Version:
4.7.4
cpe:2.3:a:wordpress:wordpress:4.7.4
Wordpress
»
Wordpress
»
Version:
4.7.5
cpe:2.3:a:wordpress:wordpress:4.7.5
Wordpress
»
Wordpress
»
Version:
4.8
cpe:2.3:a:wordpress:wordpress:4.8
Wordpress
»
Wordpress
»
Version:
4.8.1
cpe:2.3:a:wordpress:wordpress:4.8.1
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved