Vulnerabilities > Wordpress > Wordpress > 2.8.1

DATE CVE VULNERABILITY TITLE RISK
2009-08-18 CVE-2009-2853 Permissions, Privileges, and Access Controls vulnerability in Wordpress
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
network
low complexity
wordpress CWE-264
critical
10.0
2009-08-18 CVE-2009-2851 Cross-Site Scripting vulnerability in Wordpress
Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.
network
wordpress CWE-79
4.3
2009-08-13 CVE-2009-2762 Credentials Management vulnerability in Wordpress
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.
network
low complexity
wordpress CWE-255
7.5