Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:wordpress:wordpress:-:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2014-5266 |
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265. Published: August 18, 2014; 7:15:27 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2014-5265 |
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. Published: August 18, 2014; 7:15:27 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2014-5240 |
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL. Published: August 18, 2014; 7:15:27 AM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
CVE-2014-5205 |
wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack. Published: August 18, 2014; 7:15:26 AM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
CVE-2014-5204 |
wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack. Published: August 18, 2014; 7:15:26 AM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
CVE-2014-4534 |
Multiple cross-site scripting (XSS) vulnerabilities in videoplayer/autoplay.php in the HTML5 Video Player with Playlist plugin 2.4.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) theme or (2) playlistmod parameter. Published: July 02, 2014; 4:55:06 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2014-4603 |
Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid parameter. Published: July 02, 2014; 2:55:11 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2014-4600 |
Multiple cross-site scripting (XSS) vulnerabilities in contact/edit.php in the WP Ultimate Email Marketer plugin 1.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) listname or (2) contact parameter. Published: July 02, 2014; 2:55:11 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2014-4529 |
Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter. Published: July 02, 2014; 2:55:08 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2012-4915 |
Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php. Published: May 29, 2014; 10:19:06 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2014-3845 |
Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that change plugin settings via unknown vectors. NOTE: some of these details are obtained from third party information. Published: May 22, 2014; 11:13:05 AM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
CVE-2014-3844 |
The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings via unspecified vectors. NOTE: some of these details are obtained from third party information. Published: May 22, 2014; 11:13:05 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2014-3843 |
Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. Published: May 22, 2014; 11:13:05 AM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
CVE-2014-3841 |
Cross-site scripting (XSS) vulnerability in the Contact Bank plugin before 2.0.20 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Label field, related to form layout configuration. NOTE: some of these details are obtained from third party information. Published: May 22, 2014; 11:13:04 AM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2014-3210 |
SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php. Published: May 22, 2014; 11:13:03 AM -0400 |
V3.x:(not available) V2.0: 6.5 MEDIUM |
CVE-2013-2706 |
Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. Published: April 11, 2014; 10:55:05 AM -0400 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
CVE-2014-0166 |
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie. Published: April 09, 2014; 8:55:09 PM -0400 |
V3.x:(not available) V2.0: 6.4 MEDIUM |
CVE-2014-0165 |
WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php. Published: April 09, 2014; 8:55:06 PM -0400 |
V3.x:(not available) V2.0: 4.0 MEDIUM |
CVE-2012-4920 |
Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugin before 1.4.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter to index.php. Published: April 04, 2014; 10:55:04 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2013-0735 |
Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewtopic (1) remove_post, (2) sticky, or (3) closed action or (4) thread parameter in a postreply action to index.php. Published: April 02, 2014; 2:55:21 PM -0400 |
V3.x:(not available) V2.0: 7.5 HIGH |