📦 Wordpress

by Wordpress

🔍 What is Wordpress?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-36326

CRITICAL CVSS 9.8 Apr 28, 2021

This vulnerability in PHPMailer allows remote attackers to execute arbitrary code through object injection via Phar deserialization when using UNC pathnames in addAttachment. It affects PHPMailer vers...

CVE-2020-28039

CRITICAL CVSS 9.1 Nov 2, 2020

This vulnerability in WordPress allows authenticated users with author-level permissions to delete arbitrary files on the server due to improper validation of protected meta keys. It affects all WordP...

CVE-2020-28032

CRITICAL CVSS 9.8 Nov 2, 2020

CVE-2020-28032 is a critical deserialization vulnerability in WordPress that allows remote code execution. It affects WordPress sites before version 5.5.2 by exploiting improper handling of serialized...

CVE-2020-28035

CRITICAL CVSS 9.8 Nov 2, 2020

CVE-2020-28035 is a privilege escalation vulnerability in WordPress that allows attackers to gain administrative access via XML-RPC. This affects WordPress installations before version 5.5.2. Any Word...

CVE-2020-28037

CRITICAL CVSS 9.8 Nov 2, 2020

This vulnerability in WordPress allows attackers to trigger a fresh installation on an already installed WordPress site, potentially leading to remote code execution and denial of service. It affects ...

CVE-2024-4439

HIGH CVSS 7.2 May 3, 2024

WordPress Core has a stored XSS vulnerability in the Avatar block that allows attackers to inject malicious scripts via user display names. Authenticated attackers with contributor access or higher ca...

CVE-2022-21664

HIGH CVSS 7.4 Jan 6, 2022

CVE-2022-21664 is an SQL injection vulnerability in WordPress caused by insufficient input sanitization in a core class. This allows attackers to execute arbitrary SQL queries against the database. Al...

CVE-2022-21661

HIGH CVSS 8.0 Jan 6, 2022

CVE-2022-21661 is an SQL injection vulnerability in WordPress's WP_Query class due to improper input sanitization. This allows attackers to execute arbitrary SQL commands through plugins or themes tha...

CVE-2021-44223

HIGH CVSS 8.1 Nov 25, 2021

This vulnerability allows remote attackers to execute arbitrary code via supply-chain attacks against WordPress installations. Attackers can trick WordPress into updating plugins from malicious reposi...

CVE-2021-39201

HIGH CVSS 7.6 Sep 9, 2021

This vulnerability allows authenticated low-privileged WordPress users (like contributors or authors) to execute cross-site scripting (XSS) attacks in the editor, bypassing the 'unfiltered_html' permi...

CVE-2021-29447

HIGH CVSS 7.1 Apr 15, 2021

WordPress users with file upload permissions (like Authors) can exploit an XML parsing vulnerability in the Media Library to perform XXE attacks when PHP 8 is used. This allows attackers to read inter...