WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress 4.1.37 Vulnerabilities
Vulnerabilities 16
Low 3.7
2026-03-10
Medium 5.0
2024-06-25
CVE-2024-32111
N/A
2024-06-25
WordPress is vulnerable to Cross Site Scripting (XSS)
Medium 5.3
2024-04-05
CVE-2023-5692
High 8.8
2024-04-04
CVE-2024-31210
Medium 4.3
2023-10-13
CVE-2023-39999
N/A
2023-10-12
WordPress Core < 6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode
N/A
2023-05-19
WordPress Core < 6.2.1 - Shortcode Execution in User Generated Content
Medium 5.4
2023-05-17
CVE-2023-2745
N/A
2023-05-17
WordPress <= 6.2 is vulnerable to Directory Traversal
N/A
2023-05-17
WordPress <= 6.2 is vulnerable to Cross Site Scripting (XSS)
N/A
2023-05-17
WordPress <= 6.2 is vulnerable to Cross Site Request Forgery (CSRF)
N/A
2023-05-16
WordPress Core < 6.2.1 - Cross-Site Request Forgery
N/A
2023-05-16
WordPress Core < 6.2.1 - Insufficient Sanitization of Block Attributes
N/A
2023-05-16
WordPress Core < 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Embed Discovery
High 7.2
2018-08-10
CVE-2018-14028