Vulnerabilities
Vulnerable Software
Wordpress:  >> Wordpress  >> 4.1.32  Security Vulnerabilities
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.
CVSS Score
5.8
EPSS Score
0.023
Published
2019-12-26
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
CVSS Score
6.1
EPSS Score
0.034
Published
2019-10-17
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
CVSS Score
7.5
EPSS Score
0.036
Published
2019-10-17
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
CVSS Score
5.4
EPSS Score
0.018
Published
2019-10-17
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
CVSS Score
8.8
EPSS Score
0.042
Published
2019-10-17
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
CVSS Score
9.8
EPSS Score
0.111
Published
2019-10-17
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
CVSS Score
9.8
EPSS Score
0.048
Published
2019-10-17
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
CVSS Score
5.3
EPSS Score
0.729
Published
2019-10-17
WordPress before 5.2.3 allows reflected XSS in the dashboard.
CVSS Score
6.1
EPSS Score
0.011
Published
2019-09-11
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
CVSS Score
6.1
EPSS Score
0.016
Published
2019-09-11


Contact Us

Shodan ® - All rights reserved