Vulnerabilities
Vulnerable Software
Wordpress:  >> Wordpress  >> 4.2.7  Security Vulnerabilities
WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.
CVSS Score
8.6
EPSS Score
0.005
Published
2016-08-07
WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.012
Published
2016-06-29
WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.
CVSS Score
7.5
EPSS Score
0.016
Published
2016-06-29
WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.008
Published
2016-06-29
The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.052
Published
2016-06-29
WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.
CVSS Score
7.5
EPSS Score
0.018
Published
2016-06-29
Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.
CVSS Score
6.1
EPSS Score
0.008
Published
2016-06-29
Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.
CVSS Score
6.1
EPSS Score
0.008
Published
2016-06-29
The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.016
Published
2016-06-29
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."
CVSS Score
6.1
EPSS Score
0.039
Published
2016-05-22


Contact Us

Shodan ® - All rights reserved