Уязвимости

Рейтинг: 4.9 из 11 оценок

База данных уязвимостей тем и плагинов под WordPress от сервиса WPScan по состоянию на текущий день.

Содержание

WordPress 5.6-5.7 - Authenticated XXE Within the Media Library Affecting PHP 8

WordPress 4.7-5.7 - Authenticated Password Protected Pages Exposure

WordPress 3.7 to 5.7.1 - Object Injection in PHPMailer

WordPress 5.4 to 5.8 - Data Exposure via REST API

WordPress 5.4 to 5.8 - Authenticated XSS in Block Editor

WordPress 5.4 to 5.8 - Lodash Library Update

WordPress < 5.8.2 - Expired DST Root CA X3 Certificate

WordPress < 5.8.3 - SQL Injection via WP_Query

WordPress < 5.8.3 - Author+ Stored XSS via Post Slugs

WordPress 4.1-5.8.2 - SQL Injection via WP_Meta_Query

WordPress < 5.8.3 - Super Admin Object Injection in Multisites

WordPress < 5.9.2 - Prototype Pollution in jQuery

WordPress < 5.9.2 / Gutenberg < 12.7.2 - Prototype Pollution via Gutenberg’s wordpress/url package

WP < 6.0.2 - Reflected Cross-Site Scripting

WP < 6.0.2 - Authenticated Stored Cross-Site Scripting

WP < 6.0.2 - SQLi via Link API

WP < 6.0.3 - Stored XSS via wp-mail.php

WP < 6.0.3 - Open Redirect via wp_nonce_ays

WP < 6.0.3 - Email Address Disclosure via wp-mail.php

WP < 6.0.3 - Reflected XSS via SQLi in Media Library

WP < 6.0.3 - CSRF in wp-trackback.php

WP < 6.0.3 - Stored XSS via the Customizer

WP < 6.0.3 - Stored XSS via Comment Editing

WP < 6.0.3 - Content from Multipart Emails Leaked

WP < 6.0.3 - SQLi in WP_Date_Query

WP < 6.0.3 - Stored XSS via RSS Widget

WP < 6.0.3 - Data Exposure via REST Terms/Tags Endpoint

WP < 6.0.3 - Multiple Stored XSS via Gutenberg

WP <= 6.2 - Unauthenticated Blind SSRF via DNS Rebinding

WP < 6.2.1 - Directory Traversal via Translation Files

WP < 6.2.1 - Thumbnail Image Update via CSRF

WP < 6.2.1 - Contributor+ Stored XSS via Open Embed Auto Discovery

WP < 6.2.2 - Shortcode Execution in User Generated Data

WP < 6.2.1 - Contributor+ Content Injection

WP 5.6-6.3.1 - Reflected XSS via Application Password Requests

WP < 6.3.2 - Denial of Service via Cache Poisoning

WP < 6.3.2 - Subscriber+ Arbitrary Shortcode Execution

WP < 6.3.2 - Contributor+ Comment Disclosure

WP < 6.3.2 - Unauthenticated Post Author Email Disclosure

WordPress < 6.4.3 - Deserialization of Untrusted Data

WordPress < 6.4.3 - Admin+ PHP File Upload