WordPress / Wordpress-Develop
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-31211 | Remote Code Execution in `WP_HTML_Token` | CRITICAL | 9.8 | Apr 4, 2024 |
| CVE-2024-31210 | PHP file upload bypass via Plugin installer | HIGH | 8.8 | Apr 4, 2024 |
| CVE-2022-21662 | Stored XSS in WordPress | HIGH | 8.0 | Jan 6, 2022 |
| CVE-2022-21663 | Authenticated Object Injection in Multisites in WordPress | HIGH | 7.2 | Jan 6, 2022 |
| CVE-2022-21664 | SQL injection in WordPress | HIGH | 8.8 | Jan 6, 2022 |
| CVE-2022-21661 | SQL injection in WordPress | HIGH | 8.0 | Jan 6, 2022 |
| CVE-2021-39203 | Private data disclosure/privilege escalation through the block editor in Wordpress | MEDIUM | 6.8 | Sep 9, 2021 |
| CVE-2021-39202 | WordPress 5.8 beta: Stored Cross-Site Scripting (XSS) vulnerability in widget | HIGH | 7.6 | Sep 9, 2021 |
| CVE-2021-39201 | Authenticated cross-site scripting (XSS) in WordPress editor | HIGH | 7.6 | Sep 9, 2021 |
| CVE-2021-39200 | Information Disclosure in wp_die() via JSONP in wordpress | MEDIUM | 5.3 | Sep 9, 2021 |
| CVE-2021-29450 | WordPress Authenticated disclosure of password-protected posts and pages | MEDIUM | 6.5 | Apr 15, 2021 |
| CVE-2021-29447 | WordPress Authenticated XXE attack when installation is running PHP 8 | HIGH | 7.1 | Apr 15, 2021 |
| CVE-2020-4047 | Authenticated XSS via media attachment page in WordPress | MEDIUM | 6.8 | Jun 12, 2020 |
| CVE-2020-4048 | Open redirect in wp_validate_redirect() in WordPress | MEDIUM | 5.7 | Jun 12, 2020 |
| CVE-2020-4049 | Authenticated self-XSS via theme uploads in WordPress | LOW | 2.4 | Jun 12, 2020 |
| CVE-2020-4050 | set-screen-option filter misuse by plugins leading to privilege escalation in WordPress | LOW | 3.5 | Jun 12, 2020 |
| CVE-2020-4046 | Authenticated XSS through embed block in WordPress | MEDIUM | 5.4 | Jun 12, 2020 |
Showing 1 to 17 of 17 CVEs