WordPress 3.0.6 Vulnerabilities

Vulnerabilities 111
Medium 5.4
2024-10-16

CVE-2022-4973

Critical 9.8
2022-06-30

CVE-2013-4144

High 8.8
2022-05-17

Medium 6.5
2022-05-14

Medium 6.1
2022-05-14

Medium 5.4
2022-05-14

Medium 5.4
2022-05-14

High 7.5
2022-05-13

N/A
2022-03-11

WordPress <= 5.9.1 - Stored Cross-Site Scripting (XSS) vulnerability

N/A
2021-11-10

WordPress core <= 5.8.1 - Expired DST Root CA X3 Certificate issue

N/A
2021-09-09

WordPress core <= 5.8 - Command injection vulnerability in the Lodash library

N/A
2021-05-13

WordPress <= 5.7.1 - Object injection in PHPMailer vulnerability

Critical 9.8
2021-04-28

CVE-2020-36326

N/A
2021-04-15

WordPress core 4.7-5.7 - Sensitive Data Exposure vulnerability

N/A
2020-10-29

WordPress <= 5.5.1 - XML-RPC Privilege Escalation vulnerability

N/A
2019-12-13

WordPress <= 5.3 - Stored Cross-Site Scripting (XSS) vulnerability

N/A
2019-10-15

WordPress <= 5.2.3 - Multiple security issues (XSS, SSRF, Cache Poisoning)

N/A
2019-09-05

WordPress core <= 5.2.2 - Cross-Site Scripting (XSS) vulnerability

N/A
2019-03-13

WordPress 3.9-5.1 - Cross-Site Scripting (XSS) vulnerability

N/A
2018-12-13

WordPress <= 5.0 - Authenticated File Delete vulnerability

N/A
2018-12-13

WordPress <= 5.0 - Authenticated Post Type Bypass vulnerability

N/A
2018-12-13

WordPress <= 5.0 - PHP Object Injection via Meta Data vulnerability

N/A
2018-12-13

WordPress <= 5.0 - Authenticated Cross-Site Scripting (XSS) vulnerability

N/A
2018-12-13

WordPress <= 5.0 - Cross-Site Scripting (XSS) vulnerability that could affect plugins

N/A
2018-12-13

WordPress <= 5.0 - User Activation Screen Search Engine Indexing

N/A
2018-12-13

WordPress <= 5.0 - File Upload to XSS on Apache Web Servers vulnerability

High 7.2
2018-08-10

CVE-2018-14028

N/A
2018-04-05

WordPress <=4.9.4 - Vulnerable due to "localhost" default parameter

N/A
2018-04-05

WordPress <=4.9.4 - Use Safe Redirect for Login

N/A
2018-04-05

WordPress <=4.9.4 - Escape Version in Generator Tag

N/A
2018-01-17

WordPress 3.7-4.9.1 - Cross-Site Scripting vulnerability

N/A
2017-12-01

WordPress <=4.9 - Authenticated JavaScript File Upload vulnerability

N/A
2017-10-31

WordPress <=4.8.2 - potential SQL injection (SQLi), $wpdb->prepare() issue, possible unsafe queries

N/A
2017-09-19

WordPress <=4.8.1 - SQL injection (SQLi) vulnerability

N/A
2017-09-19

WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (oEmbed)

N/A
2017-09-19

WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (visual editor)

N/A
2017-09-19

WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (plugin editor)

N/A
2017-09-19

WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (template names)

N/A
2017-09-19

WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (link modal)

N/A
2017-09-19

WordPress <=4.8.1 - Path traversal vulnerability (file unzipping code)

N/A
2017-09-19

WordPress <=4.8.1 - Path traversal vulnerability (customizer)

N/A
2017-09-19

WordPress <=4.8.1 - Open redirect vulnerability (user and term edit screens)

N/A
2016-07-12

WordPress <= 4.5.3 - Path traversal

N/A
2015-04-27

WordPress <= 4.2 - Stored XSS

N/A
2014-04-09

WordPress Core < 3.8.2 - SQL Injection

N/A
2013-10-14

WordPress <=3.6 - URL Redirect Restriction Bypass

N/A
2012-09-18

WordPress 3.4.2 - Multiple Path Dislosure Vulnerabilities

N/A
2012-01-30

CVE-2012-0937

N/A
2012-01-30

CVE-2011-4899

N/A
2011-12-26

WordPress vulnerable to arbitrary PHP code execution

N/A
2011-12-26

WordPress Japanese vulnerable to cross-site scripting

N/A
2011-09-26

WordPress DEV Blogs MU 1.2.6 - HTML Injection Vulnerability

N/A
2011-09-26

WordPress Regular Subscriber Plugin 3.1.x - HTML Injection Vulnerability

N/A
2011-07-01

WordPress 3.1.3 - SQL Injection Vulnerabilities