WordPress 4.3.28 Vulnerabilities

Vulnerabilities 53
Medium 5.4
2024-10-16

CVE-2022-4973

N/A
2024-06-25

WordPress is vulnerable to Cross Site Scripting (XSS)

High 8.8
2024-04-04

CVE-2024-31210

N/A
2023-10-12

WordPress Core < 6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode

N/A
2023-05-19

WordPress Core < 6.2.1 - Shortcode Execution in User Generated Content

N/A
2023-05-17

WordPress <= 6.2 is vulnerable to Directory Traversal

N/A
2023-05-17

WordPress <= 6.2 is vulnerable to Cross Site Scripting (XSS)

N/A
2023-05-17

WordPress <= 6.2 is vulnerable to Cross Site Request Forgery (CSRF)

N/A
2023-05-16

WordPress Core < 6.2.1 - Cross-Site Request Forgery

N/A
2023-05-16

WordPress Core < 6.2.1 - Insufficient Sanitization of Block Attributes

N/A
2023-05-16

WordPress Core < 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Embed Discovery

Medium 6.1
2022-12-05

CVE-2022-43500

Medium 6.1
2022-12-05

CVE-2022-43497

N/A
2022-11-08

Multiple vulnerabilities in WordPress

N/A
2022-10-18

WordPress core <= 6.0.2 - Data Exposure vulnerability via REST API

N/A
2022-10-18

WordPress core <= 6.0.2 - Sender’s Email Address Exposure vulnerability

N/A
2022-10-18

WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability

N/A
2022-10-18

WordPress core <= 6.0.2 - Cross-Site Scripting (XSS) vulnerability

N/A
2022-10-18

WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability

N/A
2022-10-18

WordPress core <= 6.0.2 - Reflected Cross-Site Scripting (XSS) vulnerability

N/A
2022-10-18

WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability in Comment editing

N/A
2022-10-18

WordPress core <= 6.0.2 - Cross-Site Scripting (XSS) vulnerability

N/A
2022-10-18

WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability

N/A
2022-10-18

WordPress core <= 6.0.2 - Cross-Site Scripting (XSS) vulnerability

N/A
2022-10-18

WordPress core <= 6.0.2 - SQL Injection (SQLi) vulnerability

N/A
2022-10-18

WordPress core <= 6.0.2 - Content From Multipart Emails Leak vulnerability

N/A
2022-10-18

WordPress core <= 6.0.2 - Cross-Site Request Forgery (CSRF) vulnerability in wp-trackback.php

N/A
2022-10-18

WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability

N/A
2022-10-18

WordPress core <= 6.0.2 - Open redirect vulnerability

N/A
2022-10-18

WordPress Core < 6.0.3 - Shared User Instance Weakness

N/A
2022-10-18

WordPress Core < 6.0.3 - Open Redirect

N/A
2022-10-18

WordPress Core < 6.0.3 - Information Disclosure (Multi-Part Email Leak)

N/A
2022-10-18

WordPress Core < 6.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Customizer

N/A
2022-10-18

WordPress Core < 6.0.3 - Authenticated Information Disclosure via REST-API

N/A
2022-10-18

WordPress Core < 6.0.3 - Reflected Cross-Site Scripting via SQL Injection

N/A
2022-10-18

WordPress Core < 6.0.3 - Cross-Site Request Forgery via wp-trackback.php

N/A
2022-10-18

WordPress Core < 6.0.3 - Information Disclosure (Email Address)

N/A
2022-10-18

WordPress Core < 6.0.3 - Authenticated (Editor+) Stored Cross-Site Scripting via Comments

N/A
2022-10-18

WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query

N/A
2022-08-31

WordPress <= 6.0.1 - Authenticated Cross-Site Scripting (XSS) vulnerability

N/A
2022-08-31

WordPress <= 6.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

N/A
2022-08-31

WordPress <= 6.0.1 - Authenticated SQL Injection (SQLi) vulnerability via Link API

N/A
2022-08-30

WordPress Core < 6.0.2 - Authenticated SQL Injection

N/A
2022-08-30

WordPress Core < 6.0.2 - Stored Cross-Site Scripting via Plugin Deactivation and Deletion Errors

N/A
2022-08-30

WordPress Core < 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function

High 7.2
2018-08-10

CVE-2018-14028