WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress 4.0.10 Vulnerabilities
CVE-2021-29476
CVE-2022-4973
WordPress Core < 6.2.1 - Cross-Site Request Forgery
CVE-2022-3590
CVE-2022-43504
CVE-2022-43500
CVE-2022-43497
Multiple vulnerabilities in WordPress
WordPress core <= 6.0.2 - Data Exposure vulnerability via REST API
WordPress core <= 6.0.2 - Sender’s Email Address Exposure vulnerability
WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability
WordPress core <= 6.0.2 - Cross-Site Scripting (XSS) vulnerability
WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability
WordPress core <= 6.0.2 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability in Comment editing
WordPress core <= 6.0.2 - Cross-Site Scripting (XSS) vulnerability
WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability
WordPress core <= 6.0.2 - Cross-Site Scripting (XSS) vulnerability
WordPress core <= 6.0.2 - SQL Injection (SQLi) vulnerability
WordPress core <= 6.0.2 - Content From Multipart Emails Leak vulnerability
WordPress core <= 6.0.2 - Cross-Site Request Forgery (CSRF) vulnerability in wp-trackback.php
WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability
WordPress core <= 6.0.2 - Open redirect vulnerability
WordPress Core < 6.0.3 - Shared User Instance Weakness
WordPress Core < 6.0.3 - Open Redirect
WordPress Core < 6.0.3 - Information Disclosure (Multi-Part Email Leak)
WordPress Core < 6.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Customizer
WordPress Core < 6.0.3 - Authenticated Information Disclosure via REST-API
WordPress Core < 6.0.3 - Reflected Cross-Site Scripting via SQL Injection
WordPress Core < 6.0.3 - Cross-Site Request Forgery via wp-trackback.php
WordPress Core < 6.0.3 - Information Disclosure (Email Address)
WordPress Core < 6.0.3 - Authenticated (Editor+) Stored Cross-Site Scripting via Comments
WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query
WordPress <= 6.0.1 - Authenticated Cross-Site Scripting (XSS) vulnerability
WordPress <= 6.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress <= 6.0.1 - Authenticated SQL Injection (SQLi) vulnerability via Link API
WordPress Core < 6.0.2 - Authenticated SQL Injection
WordPress Core < 6.0.2 - Stored Cross-Site Scripting via Plugin Deactivation and Deletion Errors
WordPress Core < 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function
WordPress <= 5.9.1 - Stored Cross-Site Scripting (XSS) vulnerability
WordPress Core 5.9 - 5.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Core < 5.9.1 - jQuery Prototype Pollution
CVE-2022-21662
CVE-2022-21663
CVE-2021-44223
WordPress core <= 5.8.1 - Expired DST Root CA X3 Certificate issue
WordPress Core < 5.8.2 - ca-bundle.crt contains expired certificate DST Root CA X3
WordPress core <= 5.8 - Command injection vulnerability in the Lodash library
WordPress Core < 5.8.1 - LoDash Update
WordPress <= 5.7.1 - Object injection in PHPMailer vulnerability
CVE-2020-36326
CVE-2021-20083
WordPress core 4.7-5.7 - Sensitive Data Exposure vulnerability
CVE-2020-28032
CVE-2020-28033
CVE-2020-28034
CVE-2020-28035
CVE-2020-28036
CVE-2020-28037
CVE-2020-28038
CVE-2020-28039
CVE-2020-28040
WordPress <= 5.5.1 - XML-RPC Privilege Escalation vulnerability
CVE-2020-4046
CVE-2020-4047
CVE-2020-4048
CVE-2020-4049
CVE-2020-4050
CVE-2020-11025
CVE-2020-11026
CVE-2020-11027
CVE-2020-11028
CVE-2020-11029
CVE-2020-11030
WordPress <= 5.3 - wp_kses_bad_protocol() Colon Bypass vulnerability
CVE-2019-20042
CVE-2019-20043
CVE-2019-16780
CVE-2019-16781
WordPress <= 5.3 - Stored Cross-Site Scripting (XSS) vulnerability
CVE-2019-17669
CVE-2019-17670
CVE-2019-17674
CVE-2019-17675
CVE-2019-17673
CVE-2019-17671
CVE-2019-17672
WordPress <= 5.2.3 - Multiple security issues (XSS, SSRF, Cache Poisoning)
CVE-2019-16217
CVE-2019-16218
CVE-2019-16220
CVE-2019-16221
CVE-2019-16222
CVE-2019-16223
WordPress core <= 5.2.2 - Cross-Site Scripting (XSS) vulnerability
CVE-2017-6514
WordPress Core < 5.1.1 - Cross-Site Request Forgery to Cross-Site Scripting via Comments
WordPress 3.9-5.1 - Cross-Site Scripting (XSS) vulnerability
WordPress 3.7-5.0 (except 4.9.9) - Authenticated Code Execution vulnerability
CVE-2019-8943
CVE-2018-20147
CVE-2018-20151
CVE-2018-20152
CVE-2018-20153
CVE-2018-20148
CVE-2018-20149
CVE-2018-20150
WordPress <= 5.0 - Authenticated File Delete vulnerability
WordPress <= 5.0 - Authenticated Post Type Bypass vulnerability
WordPress <= 5.0 - PHP Object Injection via Meta Data vulnerability
WordPress <= 5.0 - Authenticated Cross-Site Scripting (XSS) vulnerability
WordPress <= 5.0 - Cross-Site Scripting (XSS) vulnerability that could affect plugins
WordPress <= 5.0 - User Activation Screen Search Engine Indexing
WordPress <= 5.0 - File Upload to XSS on Apache Web Servers vulnerability
CVE-2017-1000600
CVE-2018-1000773
CVE-2018-14028
WordPress Core < 6.4.3 - Authenticated(Administrator+) PHP File Upload
WordPress Core < 4.9.7 - Authenticated Arbitrary File Deletion
CVE-2018-10100
CVE-2018-10101
CVE-2018-10102
CVE-2014-6412
WordPress <=4.9.4 - Vulnerable due to "localhost" default parameter
WordPress <=4.9.4 - Use Safe Redirect for Login
WordPress <=4.9.4 - Escape Version in Generator Tag
CVE-2018-6389
CVE-2018-5776
WordPress 3.7-4.9.1 - Cross-Site Scripting vulnerability
CVE-2017-17091
CVE-2017-17092
CVE-2017-17093
CVE-2017-17094
WordPress <=4.9 - Authenticated JavaScript File Upload vulnerability
CVE-2017-16510
WordPress <=4.8.2 - potential SQL injection (SQLi), $wpdb->prepare() issue, possible unsafe queries
CVE-2012-6707
CVE-2016-9263
WordPress Core - All Known Versions - Cleartext Storage of wp_signups.activation_key
CVE-2017-14722
CVE-2017-14723
CVE-2017-14724
CVE-2017-14718
CVE-2017-14720
CVE-2017-14719
CVE-2017-14725
CVE-2017-14721
CVE-2017-14726
WordPress <=4.8.1 - SQL injection (SQLi) vulnerability
WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (oEmbed)
WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (visual editor)
WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (plugin editor)
WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (template names)
WordPress <=4.8.1 - Cross-Site Scripting (XSS) vulnerability (link modal)
WordPress <=4.8.1 - Path traversal vulnerability (file unzipping code)
WordPress <=4.8.1 - Path traversal vulnerability (customizer)
WordPress <=4.8.1 - Open redirect vulnerability (user and term edit screens)
CVE-2017-9061
CVE-2017-9062
CVE-2017-9063
CVE-2017-9064
CVE-2017-9065
CVE-2017-9066
CVE-2017-8295
WordPress <=4.7.4 - Host Header Injection in Password Reset
CVE-2017-6814
CVE-2017-6815
CVE-2017-6817
CVE-2017-5611
CVE-2016-6896
CVE-2016-10148
CVE-2017-5488
CVE-2017-5490
CVE-2017-5492
CVE-2017-5491
CVE-2017-5493
CVE-2016-7168
CVE-2016-7169
WordPress Core < 4.5 - Server-Side Request Forgery
CVE-2016-6634
CVE-2016-6635
WordPress <= 4.5.3 - Path traversal
CVE-2016-5835
CVE-2016-5837
CVE-2016-4566