Vulnerabilities > Wordpress > High

DATE CVE VULNERABILITY TITLE RISK
2019-10-17 CVE-2019-17673 WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
network
low complexity
wordpress debian
7.5
2019-03-14 CVE-2019-9787 Cross-Site Request Forgery (CSRF) vulnerability in Wordpress
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration.
network
low complexity
wordpress CWE-352
8.8
2019-02-20 CVE-2019-8942 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring.
network
low complexity
wordpress debian CWE-434
8.8
2018-12-14 CVE-2018-20151 Information Exposure vulnerability in multiple products
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen.
network
low complexity
wordpress debian CWE-200
7.5
2018-11-16 CVE-2018-19296 PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. 8.8
2018-09-06 CVE-2018-1000773 Improper Input Validation vulnerability in Wordpress
WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600.
network
low complexity
wordpress CWE-20
8.8
2018-09-06 CVE-2017-1000600 Improper Input Validation vulnerability in Wordpress
WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution.
network
low complexity
wordpress CWE-20
8.8
2018-08-10 CVE-2018-14028 Unrestricted Upload of File with Dangerous Type vulnerability in Wordpress 4.9.7
In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files.
network
low complexity
wordpress CWE-434
7.2
2018-06-26 CVE-2018-12895 Path Traversal vulnerability in multiple products
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file.
network
low complexity
wordpress debian CWE-22
8.8
2018-04-12 CVE-2014-6412 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Wordpress
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
network
high complexity
wordpress CWE-640
8.1