Vulnerabilities
Vulnerable Software
Wordpress:  >> Wordpress  >> 1.3  Security Vulnerabilities
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
CVSS Score
8.8
EPSS Score
0.042
Published
2019-10-17
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
CVSS Score
9.8
EPSS Score
0.11
Published
2019-10-17
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
CVSS Score
9.8
EPSS Score
0.048
Published
2019-10-17
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
CVSS Score
5.3
EPSS Score
0.71
Published
2019-10-17
WordPress before 5.2.3 allows reflected XSS in the dashboard.
CVSS Score
6.1
EPSS Score
0.022
Published
2019-09-11
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
CVSS Score
6.1
EPSS Score
0.026
Published
2019-09-11
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
CVSS Score
5.4
EPSS Score
0.051
Published
2019-09-11
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
CVSS Score
6.1
EPSS Score
0.027
Published
2019-09-11
WordPress before 5.2.3 allows XSS in stored comments.
CVSS Score
6.1
EPSS Score
0.022
Published
2019-09-11
WordPress before 5.2.3 allows XSS in shortcode previews.
CVSS Score
6.1
EPSS Score
0.042
Published
2019-09-11


Contact Us

Shodan ® - All rights reserved