RSS   Vulnerabilities for 'Wordpress'   RSS

2017-10-02
 
CVE-2017-14990

 

 
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

 
2017-09-23
 
CVE-2017-14726

 

 
Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

 
 
CVE-2017-14725

 

 
Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

 
 
CVE-2017-14724

 

 
Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.

 
 
CVE-2017-14723

 

 
Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.

 
 
CVE-2017-14722

 

 
Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.

 
 
CVE-2017-14721

 

 
Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.

 
 
CVE-2017-14720

 

 
Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.

 
 
CVE-2017-14719

 

 
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.

 
 
CVE-2017-14718

 

 
Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.

 


Copyright 2017, cxsecurity.com

 

Back to Top