WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress 6.3 Vulnerabilities
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
CVE-2024-31111
CVE-2024-6307
WordPress is vulnerable to Cross Site Scripting (XSS)
CVE-2024-32111
CVE-2024-31111
CVE-2024-6307
WordPress is vulnerable to Cross Site Scripting (XSS)
CVE-2024-32111
CVE-2024-31111
CVE-2024-6307
WordPress is vulnerable to Cross Site Scripting (XSS)
CVE-2024-32111
CVE-2024-31111
CVE-2024-6307
WordPress is vulnerable to Cross Site Scripting (XSS)
CVE-2024-32111
CVE-2024-31111
CVE-2024-6307
WordPress is vulnerable to Cross Site Scripting (XSS)
CVE-2024-4439
CVE-2024-4439
CVE-2024-4439
CVE-2024-4439
CVE-2023-5692
CVE-2023-5692
CVE-2023-5692
CVE-2024-31210
CVE-2024-31210
CVE-2024-31210
CVE-2023-5561
CVE-2023-5561
CVE-2023-39999
CVE-2023-39999
WordPress Core 6.3 - 6.3.1 - Authenticated(Contributor+) Cross-Site Scripting via Footnotes Block
WordPress Core 4.7.0-6.3.1 - Denial of Service via Cache Poisoning
WordPress Core < 6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode
WordPress Core 5.6 - 6.3.1 - Reflected Cross-Site Scripting via Application Password Requests
WordPress Core 6.3 - 6.3.1 - Authenticated(Contributor+) Cross-Site Scripting via Footnotes Block
WordPress Core 4.7.0-6.3.1 - Denial of Service via Cache Poisoning
WordPress Core < 6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode
WordPress Core 5.6 - 6.3.1 - Reflected Cross-Site Scripting via Application Password Requests
CVE-2018-14028
CVE-2018-14028