Vulnerabilities > Wordpress
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-08-18 | CVE-2014-5266 | Resource Management Errors vulnerability in multiple products The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265. | 5.0 |
2014-08-18 | CVE-2014-5265 | Resource Management Errors vulnerability in multiple products The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | 5.0 |
2014-08-18 | CVE-2014-5240 | Cross-Site Scripting vulnerability in multiple products Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL. | 2.1 |
2014-08-18 | CVE-2014-5205 | Cross-Site Request Forgery (CSRF) vulnerability in Wordpress wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack. | 6.8 |
2014-08-18 | CVE-2014-5204 | Cross-Site Request Forgery (CSRF) vulnerability in multiple products wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack. | 6.8 |
2014-08-18 | CVE-2014-5203 | Unspecified vulnerability in Wordpress 3.9.0/3.9.1 wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data. | 7.5 |
2014-07-02 | CVE-2014-4534 | Cross-Site Scripting vulnerability in Html5 Video Player With Playlist Plugin Project Html5 Video Player With Playlist Plugin Multiple cross-site scripting (XSS) vulnerabilities in videoplayer/autoplay.php in the HTML5 Video Player with Playlist plugin 2.4.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) theme or (2) playlistmod parameter. | 4.3 |
2014-07-02 | CVE-2014-4603 | Cross-Site Scripting vulnerability in Yahoo! Updates FOR Wordpress Plugin Project Yahoo! Updates FOR Wordpress Plugin Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid parameter. | 4.3 |
2014-07-02 | CVE-2014-4600 | Cross-Site Scripting vulnerability in WP Ultimate Email Marketer Project WP Ultimate Email Marketer 1.1.0 Multiple cross-site scripting (XSS) vulnerabilities in contact/edit.php in the WP Ultimate Email Marketer plugin 1.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) listname or (2) contact parameter. | 4.3 |
2014-07-02 | CVE-2014-4529 | Cross-Site Scripting vulnerability in Flash Photo Gallery Project Flash Photo Gallery Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter. | 4.3 |