{"error":0,"message":null,"data":{"core":"5.8.2","link":"https:\/\/wordpress.org\/support\/wordpress-version\/version-5-8-2\/#list-of-files-revised","vulnerability":[{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"CVE-2022-21661","name":"CVE-2022-21661","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-21661","description":"[en] WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.","date":"2022-01-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"1e6059508b86a984eb6263acda6267324322bc52","name":"WordPress <= 5.8.2 - SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-5-8-2-sql-injection-sqli-vulnerability","description":"SQL Injection (SQLi) vulnerability discovered by Ngocnb and Khuyenn (GiaoHangTietKiem JSC) in WordPress (versions <= 5.8.2).","date":"2022-01-06"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"b55ca2af08f1a22079952a7f589ea099e4207e34","name":"WordPress Core < 5.8.3 - SQL Injection via WP_Query","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-583-sql-injection-via-wp-query","description":"WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.","date":"2021-01-06"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"e5e6e3ca4aa9f69a2e45dfe3cea802af27ac9f4a","name":"WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-691-authenticated-author-xml-external-entity-injection-via-getid3-library-media-upload","description":"WordPress core is vulnerable to XML External Entity (XXE) Injection via the bundled getID3 library in all versions up to and including 6.9.1. This is due to the `GETID3_LIBXML_OPTIONS` constant including the `LIBXML_NOENT` flag, which enables XML entity substitution during parsing. When WordPress processes media files containing XML metadata (specifically iXML chunks in WAV\/RIFF\/AVI files), the getID3 library parses the XML with entity substitution enabled, allowing local file disclosure via `file:\/\/` protocol URIs. This may make it possible for authenticated attackers with Author-level access to read arbitrary files from the server.","date":"2026-03-10"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"CVE-2025-58674","name":"CVE-2025-58674","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-58674","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.","date":"2025-09-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"CVE-2025-58246","name":"CVE-2025-58246","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-58246","description":"[en] Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it.\nThis issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.","date":"2025-09-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-201","name":"Insertion of Sensitive Information Into Sent Data","description":"The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"CVE-2025-54352","name":"CVE-2025-54352","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-54352","description":"[en] WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.","date":"2025-07-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"3.7","severity":"l","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"3.7","severity":"low","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-669","name":"Incorrect Resource Transfer Between Spheres","description":"The product does not properly transfer a resource\/behavior to another sphere, or improperly imports a resource\/behavior from another sphere, in a manner that provides unintended control over that resource."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"b4ee3a3f910356716c196b24a0b0c1f4dc67ccb9","name":"WordPress <= 6.9.1 - Unauthenticated Blind Server-Side Request Forgery via XML-RPC Pingback Discovery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-691-unauthenticated-blind-server-side-request-forgery-via-xml-rpc-pingback-discovery","description":"WordPress core is vulnerable to Blind Server-Side Request Forgery in all versions up to and including 6.9.1. This is due to the `WP_HTTP_IXR_Client` class using `wp_remote_post()` instead of the safer `wp_safe_remote_post()` when making outgoing XML-RPC pingback requests. This makes it possible for unauthenticated attackers to make web requests to arbitrary internal locations originating from the WordPress server, which can be used to query and modify information from internal services.","date":"2026-03-10"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"a1f88382689e00e89795b386c7e9e1b1123a2656","name":"WordPress <= 6.9.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Navigation Menu Items","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-691-authenticated-administrator-stored-cross-site-scripting-via-navigation-menu-items","description":"WordPress Core is vulnerable to Stored Cross-Site Scripting via admin settings in various versions due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2026-03-10"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"2cad33da3ab46835b974d3116e6739a6e017ce88","name":"WordPress <= 6.9.1 - Missing Authorization to Authenticated (Author+) Sensitive Information Disclosure via query-attachments AJAX Endpoint","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-691-missing-authorization-to-authenticated-author-sensitive-information-disclosure-via-query-attachments-ajax-endpoint","description":"WordPress core is vulnerable to Missing Authorization in all versions up to and including 6.9.1. This is due to a missing capability check on the `uploadedToTitle` and `uploadedToLink` fields in the `wp_prepare_attachment_for_js()` function. When querying media attachments via the AJAX `query-attachments` endpoint, the response includes the parent post's title without verifying whether the current user has `read_post` permission on the parent post. This makes it possible for authenticated attackers with Author-level access to discover the titles of private, draft, and restricted posts that have media attachments.","date":"2026-03-10"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"5dfba19372d769bdb72b5172bae24dceb37e7120","name":"WordPress <= 6.9.1 - Cross-Site Scripting via Client-Side Template Override in Admin Area","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-691-cross-site-scripting-via-client-side-template-override-in-admin-area","description":"WordPress core is vulnerable to Cross-Site Scripting via client-side template overriding in the admin area in all versions up to and including 6.9.1. The `wp.template()` JavaScript function uses `document.getElementById()` to locate templates, which matches any HTML element by ID regardless of element type. WordPress admin templates are intended to be `<script type=\"text\/html\" id=\"tmpl-*\">` elements, but `getElementById` also matches `<div>`, `<img>`, and other injected elements. If an attacker can inject a non-script element with a matching `tmpl-*` ID, the template content is overridden with attacker-controlled HTML, which is then compiled by Underscore.js `_.template()` with JavaScript execution support. This is a conditional vulnerability that requires an existing HTML injection vector in the admin context.","date":"2026-03-10"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"251bc9c9fa1d2ce9e309a6954c5385b3062a0aea","name":"WordPress <= 6.8.2 - Authenticated (Author+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-682-authenticated-author-stored-cross-site-scripting-2","description":"WordPress Core is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-09-22"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"b3bcc45f6b996b4cdb67771c28441f774059ec4c","name":"WordPress <= 6.8.2 - Authenticated (Contributor+) Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-682-authenticated-contributor-sensitive-information-exposure","description":"WordPress Core is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.8.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract information from posts they should not have access to.","date":"2025-09-22"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"EUVD-2025-30913","name":"EUVD-2025-30913","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-30913","description":"Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it.This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.","date":"2025-09-23"}],"impact":{"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":null,"impact":null}}},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"EUVD-2025-30923","name":"EUVD-2025-30923","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-30923","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS. WordPress core security team is aware of the issue and working on a fix. This is low severity vulnerability that requires an attacker to have Author or higher user privileges to execute the attack vector.This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.","date":"2025-09-23"}],"impact":{"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":null,"impact":null}}},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"EUVD-2025-22048","name":"EUVD-2025-22048","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-22048","description":"WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.","date":"2025-07-21"}],"impact":{"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"3.7","severity":"low","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":null,"impact":null},"epss":"0.001"}},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"CVE-2026-64638","name":"CVE-2026-64638","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-64638","description":"[en] WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.\r\n\r\nVia a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.\r\n\r\nThis issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.\r\n\r\nDiscovered and responsibly disclosed by [the team at pwn.ai](https:\/\/pwn.ai\/).","date":"2026-08-07"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"2cd9d3c4290e67761132f0382522fae94d0a35e0","name":"WordPress Core <= 7.0.2 - Authenticated (Subscriber+) Email Change Confirmation Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-702-authenticated-subscriber-email-change-confirmation-bypass","description":"WordPress Core is vulnerable to an Email Change Confirmation Bypass in all versions up to, and including, 7.0.2 due to inconsistent validation of the new email address when a user profile is updated. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the email address on their account without completing the ownership confirmation step.","date":"2026-08-08"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"1f9c0308eb47b05ff545d4649f9501264c76cac4","name":"WordPress Core <= 7.0.2 - Unauthenticated Blind Server-Side Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-702-unauthenticated-blind-server-side-request-forgery","description":"WordPress Core is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 7.0.2 due to insufficient validation of the destination address, as not all reserved and internal IP address ranges are blocked. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application, which can be used to enumerate and interact with internal hosts and services that are otherwise not reachable.","date":"2026-08-08"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"f9a6acc74b39289ba53f875b662bccf78b95a2cb","name":"WordPress Core <= 7.0.2 - Unauthenticated Reflected Cross-Site Scripting via log Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-702-unauthenticated-reflected-cross-site-scripting-via-log-parameter","description":"WordPress Core is vulnerable to Reflected Cross-Site Scripting via the 'log' parameter in all versions up to, and including, 7.0.2 due to insufficient input sanitization and output escaping of the authentication error messages rendered on the login screen. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as visiting a specially crafted, attacker-controlled page that submits a request to the vulnerable site.","date":"2026-08-08"}],"impact":[]},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"CVE-2026-65640","name":"CVE-2026-65640","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65640","description":"[en] WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher.\n\nPrerequisites:\n* Imagick and Ghostscript in use on the server\n* A malicious user with the `upload_files` capability\n\nThis issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.","date":"2026-08-17"}],"impact":{"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}]}},{"uuid":"d3427fac62ff4a97ea0895d68c3cf9556a63a6f343347f5ea0f03bd218f84c4e","name":"5.8.2","description":null,"source":[{"id":"5d6a260533612bad7c04c2490e26027560dbb042","name":"WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-703-authenticated-author-remote-code-execution-via-malicious-file-upload","description":"WordPress Core is vulnerable to Remote Code Execution in multiple release branches, including versions 4.7.0 through 7.0.3. This is due to insufficient validation in the `WP_Image_Editor_Imagick::load()` image-processing path before passing uploaded files or streams to Imagick, which can interpret attacker-supplied image-like files as PostScript-family or compressed delegate formats based on magic bytes, format specifiers, or decompressed content rather than the WordPress-accepted extension. This makes it possible for authenticated attackers, with Author-level access and above, to upload a crafted file that is processed during attachment metadata generation and may trigger unsafe ImageMagick\/Ghostscript behavior, resulting in remote code execution on sites using Imagick and Ghostscript. Unauthenticated exploitation is deployment-dependent and requires an additional public-upload plugin or theme path that sends attacker-supplied files through WordPress image metadata generation.","date":"2026-08-12"}],"impact":[]},{"uuid":"b8acefab0ce589e661ca984dd9ea5ea594b295d9788046530c1a425349b1dd04","name":"5.8.2","description":null,"source":[{"id":"CVE-2022-21662","name":"CVE-2022-21662","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-21662","description":"[en] WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript\/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.","date":"2022-01-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"b8acefab0ce589e661ca984dd9ea5ea594b295d9788046530c1a425349b1dd04","name":"5.8.2","description":null,"source":[{"id":"498d2fc950e87cecd4957229e8c39b6748a7d447","name":"WordPress <= 5.8.2 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-5-8-2-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability discovered by Karim El Ouerghemmi and Simon Scannell (SonarSource) in WordPress (versions <= 5.8.2).","date":"2022-01-06"}],"impact":[]},{"uuid":"b8acefab0ce589e661ca984dd9ea5ea594b295d9788046530c1a425349b1dd04","name":"5.8.2","description":null,"source":[{"id":"7c5b158115d5b44f009b67ba2ba886396673e2d8","name":"WordPress Core < 5.8.3 - Authenticated (Author+) Stored Cross Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-583-authenticated-author-stored-cross-site-scripting","description":"WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript\/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.","date":"2022-01-06"}],"impact":[]},{"uuid":"23323e443c597ed2248bb9cd25b90c8bf8f248d7072a0694bb37dbfe30217f3b","name":"5.8.2","description":null,"source":[{"id":"CVE-2022-21663","name":"CVE-2022-21663","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-21663","description":"[en] WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit\/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.","date":"2022-01-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-74","name":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","description":"The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component."},{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"23323e443c597ed2248bb9cd25b90c8bf8f248d7072a0694bb37dbfe30217f3b","name":"5.8.2","description":null,"source":[{"id":"c506e936c0764c2b594ead9142034e5ac375e153","name":"WordPress <= 5.8.2 - Authenticated Object Injection in Multisites","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-5-8-2-authenticated-object-injection-in-multisites","description":"Authenticated Object Injection in Multisites discovered by Simon Scannell (SonarSource) in WordPress (versions <= 5.8.2).","date":"2022-01-06"}],"impact":[]},{"uuid":"23323e443c597ed2248bb9cd25b90c8bf8f248d7072a0694bb37dbfe30217f3b","name":"5.8.2","description":null,"source":[{"id":"84b551b6d5cdcfc6bdc0bc96c42dc968e5de4d79","name":"WordPress Core < 5.8.3 - Super Admin Multi-Site Installation Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-583-super-admin-multi-site-installation-object-injection","description":"WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit\/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.","date":"2022-01-06"}],"impact":[]},{"uuid":"bcd2f0bd5ddc353db143c46b0c263e6898eba0bda574a33547648c454fcc15bd","name":"5.8.2","description":null,"source":[{"id":"CVE-2022-21664","name":"CVE-2022-21664","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-21664","description":"[en] WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 4.1.34. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.","date":"2022-01-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"bcd2f0bd5ddc353db143c46b0c263e6898eba0bda574a33547648c454fcc15bd","name":"5.8.2","description":null,"source":[{"id":"457926504f91079d556a15b8607e1a260490f591","name":"WordPress <= 5.8.2 - SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-5-8-2-sql-injection-sqli-vulnerability-1","description":"SQL Injection (SQLi) vulnerability discovered by Ben Bidner in WordPress (versions <= 5.8.2).","date":"2022-01-06"}],"impact":[]},{"uuid":"bcd2f0bd5ddc353db143c46b0c263e6898eba0bda574a33547648c454fcc15bd","name":"5.8.2","description":null,"source":[{"id":"308a822fe2713b581cddc7626be354f4b3fae4c0","name":"WordPress Core < 5.8.3 - SQL Injection via WP_Meta_Query","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-583-sql-injection-via-wp-meta-query","description":"WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 4.1.34. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.","date":"2022-01-06"}],"impact":[]},{"uuid":"872607848258c79a008ce11b8f82a6cef2ad77f4d6002d487e5a4ac4a63b8e35","name":"5.8.2","description":null,"source":[{"id":"1978c6439d4ffbda7fe77056944c54b474d60ff0","name":"WordPress <= 5.9.1 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-5-9-1-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability discovered by Ben Bidner in WordPress (versions <= 5.9.1).","date":"2022-03-11"}],"impact":[]},{"uuid":"deac546b397c3aea20536df31d5684dbec6a0515ab45b0491c691faf831d1e4a","name":"5.8.2","description":null,"source":[{"id":"f3b7aa9bc8b0e8c3f64bd2fb40359671b0fc09e5","name":"WordPress <= 6.0.1 - Authenticated Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-6-0-1-reflected-cross-site-scripting-xss-vulnerability","description":"Authenticated Cross-Site Scripting (XSS) vulnerability discovered by Khalilov Moe in WordPress <= 6.0.1\nUpdate the WordPress to the latest available version (at least 6.0.2 or another patched version).","date":"2022-08-31"}],"impact":[]},{"uuid":"22580a4651da093ff3534b650168c0c3c32ea59a750f3554de92deb37835b0af","name":"5.8.2","description":null,"source":[{"id":"f7331d6ee9602487d9421d51bbaa8d003f910b50","name":"WordPress  <= 6.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-6-0-1-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by John Blackbourn in WordPress (versions <= 6.0.1)\nUpdate the WordPress to the latest available version (at least 6.0.2 or another patched version).","date":"2022-08-31"}],"impact":[]},{"uuid":"ba03cbe51178b893be6879855932375ef7f9c453feade73f9bdb04ff36884031","name":"5.8.2","description":null,"source":[{"id":"2ec5c355e61ff7b994ccfa9ce9a87f34bf7b22f2","name":"WordPress <= 6.0.1 - Authenticated SQL Injection (SQLi) vulnerability via Link API","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-6-0-1-sql-injection-sqli-vulnerability-via-link-api","description":"Authenticated SQL Injection (SQLi) vulnerability via Link API discovered by FVD in WordPress core (versions <= 6.0.1).\nUpdate the WordPress to the latest available version (at least 6.0.2 or another patched version).","date":"2022-08-31"}],"impact":[]},{"uuid":"139eebce4478b2580cede94bf2f4314a62c8c5e8978bd3c21189cf359433e6fa","name":"5.8.2","description":null,"source":[{"id":"7ca7fdc97c224368112a3734c88a69d9d7c94000","name":"WordPress core <= 6.0.2 - Data Exposure vulnerability via REST API","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-data-exposure-vulnerability-via-rest-api","description":"Data Exposure vulnerability via REST API discovered by Than Taintor in WordPress core (versions <= 6.0.2).\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"105800b8f2950e846832de37aef9950e254409a0cd4d1929c245751118c38c30","name":"5.8.2","description":null,"source":[{"id":"ca4682638553f66010a18e13305731295b692a26","name":"WordPress core <= 6.0.2 - Sender\u2019s Email Address Exposure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-sender-s-email-address-exposure-vulnerability","description":"Sender\u2019s Email Address Exposure vulnerability via wp-mail.php was discovered by Toshitsugu Yoneyama (Mitsui Bussan Secure Directions, Inc. via JPCERT) in the WordPress core (versions <= 6.0.2).\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"7bdb3426ed2f3fa2dbad2c9f9599f10b6b8089ee3b4358330809a08e2b5beb33","name":"5.8.2","description":null,"source":[{"id":"9b32f82750891d500f0d63e3aba0555642392326","name":"WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability via wp-mail.php discovered by Toshitsugu Yoneyama (Mitsui Bussan Secure Directions, Inc. via JPCERT) in WordPress core (versions <= 6.0.2)\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"70287bbd40d33bc34ccd1de1f0db9f54ca60a818f366d8bf600b398df5151ad2","name":"5.8.2","description":null,"source":[{"id":"adb1960ffcbdecb10955812fd87563936cb4c166","name":"WordPress core <= 6.0.2 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-cross-site-scripting-xss-vulnerability-in-the-widget-block","description":"Cross-Site Scripting (XSS) vulnerability in the Widget block discovered in WordPress core (versions <= 6.0.2)\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"fcd9cb11494c554b88f79fd2694447479788c1443d2162f9d106e91c03f4974c","name":"5.8.2","description":null,"source":[{"id":"761a0083b5932c8e9df515c1e4ecea5f28ebace3","name":"WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-stored-cross-site-scripting-xss-vulnerability-2","description":"Stored Cross-Site Scripting (XSS) vulnerability via Customizer discovered by Alex Concha (WordPress security team) in WordPress core (versions <= 6.0.2).\nUpdate the WordPress WordPress wordpress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"4367bd030795cdc5a1aade83b4f1694a94e7a6002bb92ff1b083ef1e94f0455a","name":"5.8.2","description":null,"source":[{"id":"3a7544eb6007bc2de4a64e79bd36fc601cef87ba","name":"WordPress core <= 6.0.2 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability via SQL Injection (SQLi) in Media Library discovered by Ben Bidner (WordPress security team) and Marc Montpas (Automattic) in WordPress core (versions <= 6.0.2).\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"7ca436aeeca87ce7f671e2f5fa22bf28e5d5ddc827bc32b189378da89ef7d692","name":"5.8.2","description":null,"source":[{"id":"fe7f5bd1bac786a3e5ebfe17e263c6d61e96fdd5","name":"WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability in Comment editing","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-stored-cross-site-scripting-xss-vulnerability-in-comment-editing","description":"Stored Cross-Site Scripting (XSS) vulnerability in Comment editing discovered by Alex Concha (WordPress security team) in WordPress core (versions <= 6.0.2)\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"6a830a26e5082d30b005e1525a4a4e8fe875e9823f5cd9a6258a411a584f3cd3","name":"5.8.2","description":null,"source":[{"id":"b771f01a44c736d447409970cb6d825b5d040bb7","name":"WordPress core <= 6.0.2 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-cross-site-scripting-xss-vulnerability-2","description":"Cross-Site Scripting (XSS) vulnerability in the Feature Image block discovered in WordPress core (versions <= 6.0.2)\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"cf073c47b94aae967eb2f12ec162de6681c9f56405eecf9ef0b37b7d27244a75","name":"5.8.2","description":null,"source":[{"id":"190e68095cf326a45591fd3dd32a007f3a8765e4","name":"WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-stored-cross-site-scripting-xss-vulnerability-4","description":"Stored Cross-Site Scripting (XSS) vulnerability in RSS Block discovered in WordPress core (versions <= 6.0.2).\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"abd51baf56dc88d8b7336f78cf72662ebd38b869b542f86ba05104778aed37c0","name":"5.8.2","description":null,"source":[{"id":"8cf1a27ef6994f736713659e698410b8ba2a8056","name":"WordPress core <= 6.0.2 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability in the Search block discovered by Alex Concha (WP Security team) in WordPress core (versions <= 6.0.2).\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"1c346384496e0d25227782df233956c03576cc1d5b169e65a0a1bb10976da35a","name":"5.8.2","description":null,"source":[{"id":"8363372e444bd3e93c9b85bbcb2ae0999dabbad9","name":"WordPress core <= 6.0.2 - SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-sql-injection-sqli-vulnerability","description":"SQL Injection (SQLi) vulnerability due to improper sanitization in WP_Date_Query discovered by Michael Mazzolini in WordPress core (versions <= 6.0.2).\nUpdate the WordPress WordPress wordpress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"7c1d734cd16711c4a11af31cd0ec2f700a3167b1b7bce8663092aa7a1992aabc","name":"5.8.2","description":null,"source":[{"id":"cbad750e62acc4e86903df33cd4e1b73d81454b1","name":"WordPress core <= 6.0.2 - Content From Multipart Emails Leak vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-content-from-multipart-emails-leak-vulnerability","description":"Content From Multipart Emails Leak vulnerability when HTML\/plaintext used discovered by Thomas Kr\u00e4ftner in WordPress core (versions <= 6.0.2).\nUpdate the WordPress WordPress wordpress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"0e73b75b860bba684853749d424d90318da30a056555136659b24c42d500ac44","name":"5.8.2","description":null,"source":[{"id":"7fb29fe75ce5d996234e74ba1d073bf366429926","name":"WordPress core <= 6.0.2 - Cross-Site Request Forgery (CSRF) vulnerability in wp-trackback.php","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-cross-site-request-forgery-csrf-vulnerability-in-wp-trackback-php","description":"Cross-Site Request Forgery (CSRF) vulnerability in wp-trackback.php discovered by Simon Scannell in WordPress core (versions <= 6.0.2).\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"8bbc479cfc56963c7fb831a510d6e6ef8d0d36b5634e3f5da068991c63a5d562","name":"5.8.2","description":null,"source":[{"id":"99b696e0ecdb0f6d3a64b1a413467fd11dd6e763","name":"WordPress core <= 6.0.2 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-0-2-stored-cross-site-scripting-xss-vulnerability-3","description":"Stored Cross-Site Scripting (XSS) vulnerability in RSS Widget discovered in WordPress core (versions <= 6.0.2).\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"f5e6f8b5317efdabf08d5b70edf68d0f360a06899b7db8a52db19a41ff54d9f4","name":"5.8.2","description":null,"source":[{"id":"41e27e626f6edf652a6b9204bc05564d210ebdac","name":"WordPress core <= 6.0.2 - Open redirect vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpres-core-6-0-2-open-redirect-vulnerability","description":"Open redirect vulnerability in wp_nonce_ays discovered by devrayn in WordPress core (versions <= 6.0.2)\nUpdate the WordPress to the latest available version (at least 6.0.3).","date":"2022-10-18"}],"impact":[]},{"uuid":"dd3bc32d3dedbfdbfa389d0d148f17285af07ea335471fd576c3a2b8209ccbfb","name":"5.8.2","description":null,"source":[{"id":"JVNDB-2022-000087","name":"Multiple vulnerabilities in WordPress","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2022-000087","description":"WordPress contains multiple vulnerabilities listed below which are to the WordPress Post by Email Feature. <ul><li>Stored Cross-site scripting (CWE-79) - CVE-2022-43497<\/li><li>Stored Cross-site scripting (CWE-79) - CVE-2022-43500<\/li><li>Improper authentication (CWE-287) - CVE-2022-43504<\/li><\/ul> Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. reported these vulnerabilities to IPA. JPCERT\/CC coordinated with the developer under Information Security Early Warning Partnership.","date":"2022-11-08"}],"impact":[]},{"uuid":"f8b84757e2193b814c7a42a4128f0aac4022ef0a99d81bb71d9c0ad15d229b36","name":"5.8.2","description":null,"source":[{"id":"CVE-2022-43504","name":"CVE-2022-43504","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-43504","description":"[en] Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.","date":"2022-12-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f8b84757e2193b814c7a42a4128f0aac4022ef0a99d81bb71d9c0ad15d229b36","name":"5.8.2","description":null,"source":[{"id":"3db7ce2d621b875eee20a9de5430775a46208f45","name":"WordPress Core < 6.0.3 - Stored Cross-Site Scripting via wp-mail.php","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-603-stored-cross-site-scripting-via-wp-mailphp","description":"WordPress Core in versions up to 6.0.3 are vulnerable to Cross-Site Scripting via wp-mail.php. This is due to no validation on what level the user was sending the email post and therefore did not perform any sanitization on the submitted post data. This meant that users without the unfiltered_html capability, with access to submitting posts via email, could inject malicious JavaScript into posts that would execute whenever someone accessed the post. CVE-2022-43500 may be a duplicate of this issue.","date":"2022-10-18"}],"impact":[]},{"uuid":"8856e37e3cacc9f9dc27d88f4d0b14d49287adec2fa44030ef878e44665f3758","name":"5.8.2","description":null,"source":[{"id":"CVE-2022-43500","name":"CVE-2022-43500","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-43500","description":"[en] Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.","date":"2022-12-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5938f1a7861933b97ed779b4257108a0f4726d647b3b07a79804a00ea0f22b2f","name":"5.8.2","description":null,"source":[{"id":"CVE-2022-43497","name":"CVE-2022-43497","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-43497","description":"[en] Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.","date":"2022-12-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2bd14cde799e36203911ae16530bec5170aeadf1c54e47b9d1b94d31641cc9c9","name":"5.8.2","description":null,"source":[{"id":"78cb0ca6db616fea2d602146ff644e60b6f952a9","name":"WordPress Core < 6.0.3 - Shared User Instance Weakness","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-603-shared-user-instance-weakness","description":"WordPress Core in versions up to 6.0.3 had a weakness in how Share User Instances were handled. This fix appears to have been necessary to safely use the wp_set_current_user( 0 ); method to patch the previously mentioned XSS and CSRF in wp-mail.php and wp-trackback.php vulnerabilities. The previous functionality may have resulted in third party plugins or themes using the wp_set_current_user function in a way that could lead to privilege escalation and users being able to perform more actions than originally intended.","date":"2022-10-18"}],"impact":[]},{"uuid":"db81a12f466299471442bd5edf6d7effdfba4d68f0a697fb7fdf6635afbb4749","name":"5.8.2","description":null,"source":[{"id":"2e4c185cddfe91117267695bf876b39f965ae54c","name":"WordPress Core < 6.0.3 - Open Redirect","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-603-open-redirect","description":"WordPress Core is vulnerable to open redirect in versions up to 6.0.3. This is due to insufficient validation of the 'Referer' header and _wp_http_referer request parameter when a user accesses a link with an expired or invalid nonce. This would make it possible for an attacker to redirect a victim to a potentially malicious site, granted they could trick the victim into performing an action such as clicking on a link.","date":"2022-10-18"}],"impact":[]},{"uuid":"7dc1fd9e8eafaf835ef738eb1c051ba532aa30aa2e8ec5477990db429dda7736","name":"5.8.2","description":null,"source":[{"id":"190fc0bb9fef5e631087ea153589b8a8a6f90960","name":"WordPress Core < 6.0.3 - Information Disclosure (Multi-Part Email Leak)","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-603-information-disclosure-multi-part-email-leak","description":"WordPress Core is vulnerable to information disclosure via a REST-API endpoint in versions up to 6.0.3. The endpoint for terms and tags did not perform enough validation on the user requesting information about terms and tags for a given post. This made it possible for users with access to terms and tags, such as a contributor, to determine those details on all posts not belonging to them, even when in a private status. This does not reveal critical information, and as such it is not likely to be exploited.","date":"2022-10-18"}],"impact":[]},{"uuid":"b222dae05a2e48c5f94ad7462b039ffd74f2fe26b3eba4cd94a2f2af530890ba","name":"5.8.2","description":null,"source":[{"id":"965a319b01a13c6eead339996178eb24e2e0d491","name":"WordPress Core < 6.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Customizer","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-603-authenticated-admin-stored-cross-site-scripting-via-customizer","description":"WordPress Core is vulnerable to Stored Cross-Site Scripting via the Customizer in versions up to 6.0.3. This is due to insufficient escaping on the 'Blog Name' value that could be edited and become executable with the right payload while in the theme customizer. This would make it possible for authenticated attacker with access to customize a theme, such as administrators to inject malicious JavaScript into the page.","date":"2022-10-18"}],"impact":[]},{"uuid":"1e0b0d6b67ce8594fd8c78ed0d22fad2ef83fb7fcf9f8147fe59348535173d2e","name":"5.8.2","description":null,"source":[{"id":"c9323f64fe9af6b7bd7edb0c979a9855fb13e098","name":"WordPress Core < 6.0.3 - Authenticated Information Disclosure via REST-API","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-603-authenticated-information-disclosure-via-rest-api","description":"WordPress Core is vulnerable to information disclosure via the REST-API in versions up to 6.0.3. The REST API endpoint for terms and tags did not perform enough validation on the user requesting information about terms and tags for a given post. This made it possible for users with access to terms and tags, such as a contributor, to determine those details on all posts not belonging to them, even when in a private status. This does not reveal critical information.","date":"2022-10-18"}],"impact":[]},{"uuid":"faa3964cfd4f3d2cd7c918f1389facff1744603a46a197975aa6ee7f16c46119","name":"5.8.2","description":null,"source":[{"id":"63b392aea1c1b4bc1361601b817a44bafe763b06","name":"WordPress Core < 6.0.3 - Reflected Cross-Site Scripting via SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-603-reflected-cross-site-scripting-via-sql-injection","description":"WordPress Core is vulnerable to SQL Injection in the Media Library that can be leveraged to exploit a Reflected Cross-Site Scripting issue in versions up to 6.0.3. This is due to insufficient escaping on user supplied values passed to a SQL query.  This makes it possible for an attacker to achieved JavaScript code execution in a victims browser, granted they can trick the victim into performing an action such as clicking on a link.","date":"2022-10-18"}],"impact":[]},{"uuid":"b1639bc4938c4651a910902a29783a1e13178ed275ac2447008de5136b1530a4","name":"5.8.2","description":null,"source":[{"id":"9ee0cd84d77b81697234ae7dc17da7bdc5cf4e78","name":"WordPress Core < 6.0.3 - Cross-Site Request Forgery via wp-trackback.php","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-603-cross-site-request-forgery-via-wp-trackbackphp","description":"WordPress Core is vulnerable to Cross-Site Request Forgery via wp-trackback.php in versions up to 6.0.3. This is due to the fact that the any request to wp-trackback.php would assume the identity of the user whose cookies are sent with the request. This would make it possible for an unauthenticated user to trigger a trackback assuming the identity of another user, granted they could trick that other user into performing the action. In new versions of WordPress, the identity will always be a non-existent user with the ID of 0, which represents an unauthenticated user.","date":"2022-10-18"}],"impact":[]},{"uuid":"1eeb8ea3d5fa9271e8e66b87037a3e1f3bf0e7bf0711be8204c66dcb4091bc13","name":"5.8.2","description":null,"source":[{"id":"9abbc1eef7432ddae819cebac05eda27f8968cb7","name":"WordPress Core < 6.0.3 - Information Disclosure (Email Address)","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-603-information-disclosure-email-address","description":"WordPress Core is vulnerable to Information Disclosure of in versions up to 6.0.3. When the post by email functionality is enabled, it may log post author's email addresses in a way that may be publicly accessible. This could make it possible for attackers to steal post author's email addresses and use that for further attacks.","date":"2022-10-18"}],"impact":[]},{"uuid":"06892d5cf9c6b4c6810fe300946322562d3c8cc78529219d7c932cd2b8bee267","name":"5.8.2","description":null,"source":[{"id":"c090fb8976cdf06fe4a784b26e31a994810574e6","name":"WordPress Core < 6.0.3 - Authenticated (Editor+) Stored Cross-Site Scripting via Comments","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-603-authenticated-editor-stored-cross-site-scripting-via-comments","description":"WordPress Core is vulnerable to Stored Cross-Site Scripting, exploitable during comment editing, in versions up to 6.0.3. This is due to insufficient escaping and sanitization on the values being stored during a comment update. This makes it possible for authenticated users with high level permissions, such as an editor, to modify post comments to include malicious web scripts that will execute whenever someone accesses the comment.","date":"2022-10-18"}],"impact":[]},{"uuid":"aa563cc76f670df5f0528335df00a97e0e269944651abbc80f8e5a70ae57fd52","name":"5.8.2","description":null,"source":[{"id":"3125d7e18248788cbd9188f71d414ec4bb93250e","name":"WordPress Core < 6.0.3 - SQL Injection via WP_Date_Query","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-603-sql-injection-via-wp-date-query","description":"WordPress Core is vulnerable to SQL Injection in versions up to 6.0.3. This is due to insufficient escaping on where \u201cAND\u201d and \u201cOR\u201d present in the query. This may make it possible for attackers to achieve SQL Injection when another plugin or theme is installed on the site that allows WP_Date_Query to be used insecurely.","date":"2022-10-18"}],"impact":[]},{"uuid":"1698eab40878b5874a9f2cac2c460227a53e10a6852fedce99b58f8c653e7903","name":"5.8.2","description":null,"source":[{"id":"444b0c4cd5f7625ac90487b84c538374100a3f9e","name":"WordPress Core < 6.0.2 - Authenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-602-authenticated-sql-injection","description":"WordPress Core, in versions up to 6.0.2, is vulnerable to SQL Injection that can be exploited by authenticated users via the LIMIT parameter passed through the get_bookmarks function. This can be exploited on default WordPress installations by users with high-level privileges, such as an editor or administrator, and it may be possible for this to be exploited by lower-privileged users if a plugin\/theme passes an unescaped user supplied LIMIT value from those level users to the get_bookmarks function.","date":"2022-08-30"}],"impact":[]},{"uuid":"c13de2c430cf6224bdbbdf000ff8fbf73c9ac2ebfb67de232cf275b4920b7bd8","name":"5.8.2","description":null,"source":[{"id":"6d4e711f6c8b6ee331f0b1e73a4a2bd0e0ae11d2","name":"WordPress Core < 6.0.2 - Stored Cross-Site Scripting via Plugin Deactivation and Deletion Errors","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-602-stored-cross-site-scripting-via-plugin-deactivation-and-deletion-errors","description":"WordPress Core, in versions up to 6.0.2, is vulnerable to Stored Cross-Site Scripting that can be exploited when malicious content is injected into plugin code that triggers when an error occurs during plugin de-activation or during deletion. This requires an attacker have access to the modify the error message that is displayed either in the plugin's code or via a request parameter, in most cases it is likely to be the latter.","date":"2022-08-30"}],"impact":[]},{"uuid":"13ba507d89eaf4d60a505a7e7c606e6477e5f744f39509137a100bbebae142c7","name":"5.8.2","description":null,"source":[{"id":"ff2eea71b936176aa8dfa6a17182149fc32c1dac","name":"WordPress Core < 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-602-authenticated-contributor-stored-cross-site-scripting-via-use-of-the-meta-function","description":"WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that execute if the the_meta(); function is called on that page.","date":"2022-08-30"}],"impact":[]},{"uuid":"2b91f376d2761b4d4d373fb49c2e901d993803defc14bcaaf06e429104496846","name":"5.8.2","description":null,"source":[{"id":"f44964d4862c0c3f4c61975fa84be6aff69e1b26","name":"WordPress Core 5.9 - 5.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-59-591-authenticated-contributor-stored-cross-site-scripting","description":"WordPress Core in versions 5.9 - 5.9.1 is vulnerable to Contributor+ stored Cross-Site Scripting via the double JSON encoded payloads set in the 'isGlobalStylesUserThemeJSON' parameter which is updatable via the post editor.","date":"2022-03-11"}],"impact":[]},{"uuid":"f115d39951e282b1c7a2175524f183aa0e9bb9f46179130bae8ceba5cafa6aa5","name":"5.8.2","description":null,"source":[{"id":"CVE-2021-20083","name":"CVE-2021-20083","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-20083","description":"[en] Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.","date":"2021-04-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-1321","name":"Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')","description":"The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype."}]}},{"uuid":"e878ee31eb18b439ba95c45f190a3458ef86a4a4583c77a815101cce6fb173b9","name":"5.8.2","description":null,"source":[{"id":"d4c9b79e9b5d7710ce593a44669702750ee3e41a","name":"WordPress Core < 5.9.1 - jQuery Prototype Pollution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-591-jquery-prototype-pollution","description":"Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.","date":"2022-03-11"}],"impact":[]},{"uuid":"9542fc7cdf0b69d726e1a3a97afa13fa9d0e669498f35e32c83ba032ac95c927","name":"5.8.2","description":null,"source":[{"id":"CVE-2022-3590","name":"CVE-2022-3590","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-3590","description":"[en] WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.","date":"2022-12-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"5.9","severity":"m","exploitable":"2.2","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"5.9","severity":"medium","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.2","impact":"3.6"},"cwe":[{"cwe":"CWE-367","name":"Time-of-check Time-of-use (TOCTOU) Race Condition","description":"The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check."},{"cwe":"CWE-918","name":"Server-Side Request Forgery (SSRF)","description":"The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9542fc7cdf0b69d726e1a3a97afa13fa9d0e669498f35e32c83ba032ac95c927","name":"5.8.2","description":null,"source":[{"id":"e9d0ad876e071acad8bf0f2ff4a21ef953a426d9","name":"WordPress Core - All known versions - Unauthenticated Blind Server Side Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-611-unauthenticated-blind-server-side-request-forgery","description":"WordPress Core, in all known versions is vulnerable to blind Server-Side Request Forgery in its pingback feature. This is due to a Time-of-Check-Time-of-Use (TOC-TOU) race condition between validation checks and HTTP requests that makes it possible for URLs to be validated and then changed before being used by the software. This makes it possible for an attacker to change the domain in a pingback request to point to a different address than the one validated before, thus exposing hosts that should not be reachable on a server. The original researcher couldn't identify any ways to exploit this to take over vulnerable sites without other vulnerable services on the site meaning this would be difficult to exploit. The issue was first reported in 2017 and it's recommendd to block xmlrpc.php at the web server level, if not in use to prevent this from being exploited.","date":"2022-09-06"}],"impact":[]},{"uuid":"0f9d8cb1032ede8307be8978a684553b0bb8430b9140e05328a7a9a6586e1cb0","name":"5.8.2","description":null,"source":[{"id":"1a4eda6bf228066df200968ba5b74b0c8e73621a","name":"WordPress Core < 6.2.1 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-621-cross-site-request-forgery","description":"WordPress Core is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the \u2018wp_ajax_set_attachment_thumbnail\u2019 AJAX function in versions up to, and including, 6.2. This allows unauthenticated users to update the thumbnail image associated with existing attachments, granted they can trick an authenticated user with appropriate permissions into performing an action, such as clicking a link. The impact of this vulnerability is incredibly minimal.","date":"2023-05-16"}],"impact":[]},{"uuid":"21aa265cc3df71cd1f1cd762217fe67628cc953ebdce8848232c02a53266e2a5","name":"5.8.2","description":null,"source":[{"id":"CVE-2023-2745","name":"CVE-2023-2745","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2745","description":"[en] WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the \u2018wp_lang\u2019 parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.","date":"2023-05-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.2","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"high","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.2","impact":"2.7"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"21aa265cc3df71cd1f1cd762217fe67628cc953ebdce8848232c02a53266e2a5","name":"5.8.2","description":null,"source":[{"id":"1ea2f3b88b393beb180f0255a98a57e7a25ac1a5","name":"WordPress Core < 6.2.1 - Directory Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-621-directory-traversal","description":"WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the \u2018wp_lang\u2019 parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.","date":"2023-05-16"}],"impact":[]},{"uuid":"5ce514526f61b521ebf796f406d76d806047f215b25d25439493a477c97e6da3","name":"5.8.2","description":null,"source":[{"id":"771f5d225b84040886ecf416be1bbbb07b837997","name":"WordPress  <= 6.2 is vulnerable to Directory Traversal","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-2-unauth-directory-traversal-vulnerability","description":"Update the WordPress core to the latest available version (at least 6.2.1).\nRamuel Gall discovered and reported this Directory Traversal vulnerability in WordPress. This could allow a malicious actor to see all files in a given directory or determine if certain files\/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 6.2.1.","date":"2023-05-17"}],"impact":[]},{"uuid":"67ee635a94b9de5bc631610cf1f378e4b93e3808db5163caba97d8dcc174184f","name":"5.8.2","description":null,"source":[{"id":"7ad7133f8dc8558931c13f7670f48bf58d94b40b","name":"WordPress  <= 6.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-2-auth-stored-cross-site-scripting-xss-vulnerability","description":"Update the WordPress core to the latest available version (at least 6.2.1).\nJakub Zoczek (Securitum) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 6.2.1.","date":"2023-05-17"}],"impact":[]},{"uuid":"8e73ea8cc82b51ad621da30f21765512c43556f09c790f52da0495eb4679deea","name":"5.8.2","description":null,"source":[{"id":"2c7e09c181720ef6f8bc423385b618858eb6dea2","name":"WordPress  <= 6.2 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-2-cross-site-request-forgery-vulnerability","description":"Update the WordPress core to the latest available version (at least 6.2.1).\nJohn Blackbourn discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 6.2.1.","date":"2023-05-17"}],"impact":[]},{"uuid":"2d7d705ebe32f8396fbcef4f65a4ad52e24783b5384776e10669ef8e96a0ef1b","name":"5.8.2","description":null,"source":[{"id":"6e61b246-5af1-4a4f-9ca8-a8c87eb2e499","name":"WordPress &lt; 5.9.2 \/ Gutenberg &lt; 12.7.2 - Prototype Pollution via Gutenberg&rsquo;s wordpress\/url package","link":"https:\/\/wpscan.com\/vulnerability\/6e61b246-5af1-4a4f-9ca8-a8c87eb2e499","description":"The @wordpress\/url package used in WordPress and the Gutenberg plugin is affected by a Prototype Pollution issue","date":null}],"impact":[]},{"uuid":"8eecca19c86c8c423644c597fb915944963d2eca903fdf7a0bc019435e7d8103","name":"5.8.2","description":null,"source":[{"id":"6330ef03d260abd6a6fc9a2c7fee47e58d77d1ba","name":"WordPress Core < 6.2.1 - Shortcode Execution in User Generated Content","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-621-shortcode-execution-in-user-generated-content","description":"WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2. This could allow unauthenticated attackers to execute shortcodes via submitting comments or other content, allowing them to exploit vulnerabilities that typically require Subscriber or Contributor-level permissions. While this is likely to have minimal impact on its own, it can significantly increase the severity of other vulnerabilities.","date":"2023-05-19"}],"impact":[]},{"uuid":"0d6a6f337142880a4507f7e5a0cd5ddb631382e6b1f3324437319274523de68c","name":"5.8.2","description":null,"source":[{"id":"7c9fb4a43a7ca0cb81d96d348d81651d8996627f","name":"WordPress Core < 6.2.1 - Insufficient Sanitization of Block Attributes","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-621-insufficient-sanitization-of-block-attributes","description":"WordPress Core failed to sufficiently sanitize block attributes in versions up to, and including, 6.2. This makes it possible for authenticated attackers with contributor-level and above permissions to embed arbitrary content in HTML comments on the page, though Cross-Site Scripting may be possible when combined with an additional vulnerability.","date":"2023-05-16"}],"impact":[]},{"uuid":"b3157144684252eadc6bae1b63ec8228d99b3e58e69cfcbde2ea68c7fa5a451e","name":"5.8.2","description":null,"source":[{"id":"ac79173191d3029d0aab292c2fbc025440981d56","name":"WordPress Core < 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Embed Discovery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-621-authenticated-contributor-stored-cross-site-scripting-via-embed-discovery","description":"WordPress Core is vulnerable to stored Cross-Site Scripting in versions up to, and including, 6.2, due to insufficient validation of the protocol in the response when processing oEmbed discovery. This makes it possible for authenticated attackers with contributor-level and above permissions to use a crafted oEmbed payload at a remote URL to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-05-16"}],"impact":[]},{"uuid":"96033ea55981af5d5c1cf1289d0f84b809ade2700a875de2f54a37afefebbc1d","name":"5.8.2","description":null,"source":[{"id":"CVE-2023-39999","name":"CVE-2023-39999","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-39999","description":"[en] Exposure of Sensitive Information to an Unauthorized Actor in WordPress\u00a0from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.","date":"2023-10-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}]}},{"uuid":"96033ea55981af5d5c1cf1289d0f84b809ade2700a875de2f54a37afefebbc1d","name":"5.8.2","description":null,"source":[{"id":"1511f25d91c0e9fec68946b8e1b691b069bbf8ee","name":"WordPress Core <= 6.3.1 - Authenticated(Contributor+) Sensitive Information Exposure via Comments on Protected Posts","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-631-authenticatedcontributor-sensitive-information-exposure-via-comments-on-protected-posts","description":"WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.3.1 via the comments listing. This allows authenticated users, with contributor-level privileges or above, to view comments on protected posts.","date":"2023-10-12"}],"impact":[]},{"uuid":"0b8a42dc040a850415bcadc2cca745ad18d7fedf86299606c9660b20e12be2cd","name":"5.8.2","description":null,"source":[{"id":"fca0074e6b9a35c3027dc45eb006ef568911e0c6","name":"WordPress Core 4.7.0-6.3.1 - Denial of Service via Cache Poisoning","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-470-631-denial-of-service-via-cache-poisoning","description":"WordPress Core is vulnerable to Denial of Service via Cache Poisoning in versions between 4.7.0 and 6.3.1. In cases where the X-HTTP-Method-Override header was sent in a request to a REST endpoint and the endpoint returned a 4xx error, the error could be cached, resulting in denial of service.","date":"2023-10-12"}],"impact":[]},{"uuid":"73ae4e8f2ae0904811b6a596c71010a9d595ec30c2b4c3929db3005602422fcd","name":"5.8.2","description":null,"source":[{"id":"CVE-2023-5561","name":"CVE-2023-5561","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-5561","description":"[en] WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack","date":"2023-10-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}]}},{"uuid":"73ae4e8f2ae0904811b6a596c71010a9d595ec30c2b4c3929db3005602422fcd","name":"5.8.2","description":null,"source":[{"id":"fe73361608f8852cb182d301999ab12d22cb2671","name":"WordPress Core 4.7.0 - 6.3.1 - Sensitive Information Exposure via User Search REST Endpoint","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-470-631-sensitive-information-exposure-via-user-search-rest-endpoint","description":"WordPress Core is vulnerable to Sensitive Information Exposure in versions between 4.7.0 and 6.3.1 via the User REST endpoint. While the search results do not display user email addresses unless the requesting user has the 'list_users' capability, the search is applied to the user_email column. This can allow unauthenticated attackers to brute force or verify the email addresses of users with published posts or pages on the site.","date":"2023-10-12"}],"impact":[]},{"uuid":"0367c580c6cdc135c9f30d3cc9b489cac2786b799e7b20062cb4d23a462eb82d","name":"5.8.2","description":null,"source":[{"id":"0b8e53a6604663532301e3a7dfdce0ecbd91d0e6","name":"WordPress Core < 6.3.2 \u2013 Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-632-authenticated-subscriber-arbitrary-shortcode-execution-via-parse-media-shortcode","description":"WordPress Core is vulnerable to arbitrary shortcode execution in versions up to, and including, 6.3.1 due to a lack of input validation on the 'shortcode' parameter in the parse_media_shortcode AJAX function. This allows authenticated attackers, with subscriber-level privileges and above, to execute arbitrary shortcodes.","date":"2023-10-12"}],"impact":[]},{"uuid":"1908909032c489371600a7df083036e53a957239e09e9d304d25c463c58b5949","name":"5.8.2","description":null,"source":[{"id":"b0c00fea79c2e792d9402a3443141a64857675aa","name":"WordPress Core 5.6 - 6.3.1 - Reflected Cross-Site Scripting via Application Password Requests","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-56-631-reflected-cross-site-scripting-via-application-password-requests","description":"WordPress Core is vulnerable to Reflected Cross-Site Scripting via the \u2018success_url\u2019 and 'reject_url' parameters when requesting application passwords in versions between 5.6 and 6.3.1 due to insufficient input sanitization and output escaping of pseudo protocol URIs. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link and accepting or rejecting the application password.","date":"2023-10-12"}],"impact":[]},{"uuid":"a38009bb52e0c3a704393a76d356e200ba0b5f1c8d7f145ac07053634fb53de7","name":"5.8.2","description":null,"source":[{"id":"CVE-2018-14028","name":"CVE-2018-14028","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-14028","description":"[en] In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in a predictable wp-content\/uploads location, allowing for an attacker to then execute the file. This represents a security risk in limited scenarios where an attacker (who does have the required capabilities for plugin uploads) cannot simply place arbitrary PHP code into a valid plugin ZIP file and upload that plugin, because a machine's wp-content\/plugins directory permissions were set up to block all new plugins.","date":"2018-08-10"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}]}},{"uuid":"f54ca4d951e5968277f28da53324474053efde5caee81ba99b73687979049fdc","name":"5.8.2","description":null,"source":[{"id":"CVE-2023-5692","name":"CVE-2023-5692","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-5692","description":"[en] WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including,  6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.","date":"2024-04-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f54ca4d951e5968277f28da53324474053efde5caee81ba99b73687979049fdc","name":"5.8.2","description":null,"source":[{"id":"a0cf26dbffa8b765697fbd35bdd594cda1eefaff","name":"WordPress Core <= 6.4.3 - Sensitive Information Exposure via redirect_guess_404_permalink","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-643-sensitive-information-exposure-via-redirect-guess-404-permalink","description":"WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including,  6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.","date":"2024-04-04"}],"impact":[]},{"uuid":"f3bd152fd4cd71f4eaa60bc949bb7626de9920eec96893f81d2e47116b8d8211","name":"5.8.2","description":null,"source":[{"id":"CVE-2024-31210","name":"CVE-2024-31210","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-31210","description":"[en] WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for installation (in order to move the file into place outside of the `uploads` directory) then the uploaded file remains temporary available in the Media Library despite it not being allowed. If the `DISALLOW_FILE_EDIT` constant is set to `true` on the site _and_ FTP credentials are required when uploading a new theme or plugin, then this technically allows an RCE when the user would otherwise have no means of executing arbitrary PHP code. This issue _only_ affects Administrator level users on single site installations, and Super Admin level users on Multisite installations where it's otherwise expected that the user does not have permission to upload or execute arbitrary PHP code. Lower level users are not affected. Sites where the `DISALLOW_FILE_MODS` constant is set to `true` are not affected. Sites where an administrative user either does not need to enter FTP credentials or they have access to the valid FTP credentials, are not affected. The issue was fixed in WordPress 6.4.3 on January 30, 2024 and backported to versions 6.3.3, 6.2.4, 6.1.5, 6.0.7, 5.9.9, 5.8.9, 5.7.11, 5.6.13, 5.5.14, 5.4.15, 5.3.17, 5.2.20, 5.1.18, 5.0.21, 4.9.25, 2.8.24, 4.7.28, 4.6.28, 4.5.31, 4.4.32, 4.3.33, 4.2.37, and 4.1.40. A workaround is available. If the `DISALLOW_FILE_MODS` constant is defined as `true` then it will not be possible for any user to upload a plugin and therefore this issue will not be exploitable.","date":"2024-04-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"87031347d927625ae67e52bc28f8b659369a4da3843e952790fb9cef7e58db5e","name":"5.8.2","description":null,"source":[{"id":"CVE-2024-32111","name":"CVE-2024-32111","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-32111","description":"[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through 6.0.8, from 5.9 through 5.9.9, from 5.8 through 5.8.9, from 5.7 through 5.7.11, from 5.6 through 5.6.13, from 5.5 through 5.5.14, from 5.4 through 5.4.15, from 5.3 through 5.3.17, from 5.2 through 5.2.20, from 5.1 through 5.1.18, from 5.0 through 5.0.21, from 4.9 through 4.9.25, from 4.8 through 4.8.24, from 4.7 through 4.7.28, from 4.6 through 4.6.28, from 4.5 through 4.5.31, from 4.4 through 4.4.32, from 4.3 through 4.3.33, from 4.2 through 4.2.37, from 4.1 through 4.1.40.","date":"2024-06-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"h","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"5.0","severity":"m","exploitable":"1.6","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"5.0","severity":"medium","av":"network","ac":"high","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"1.6","impact":"3.4"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"87031347d927625ae67e52bc28f8b659369a4da3843e952790fb9cef7e58db5e","name":"5.8.2","description":null,"source":[{"id":"13c8011a2ae29c043682e4a7786cf8ccff148e3c","name":"WordPress Core < 6.5.5 - Authenticated (Contributor+) Directory Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-core\/wordpress-core-655-authenticated-contributor-directory-traversal?asset_slug=wordpress","description":"WordPress Core is vulnerable to Directory Traversal in various versions up to 6.5.5 via the Template Part block. This makes it possible for authenticated attackers, with Contributor-level access and above, to include arbitrary HTML Files on sites running Windows.","date":"2024-06-24"}],"impact":[]},{"uuid":"9932fbf46db62047d5b6f93b2eb83ac396355df315094b87c96d60ef52b2f2c4","name":"5.8.2","description":null,"source":[{"id":"f64f0b84279167df76c7697c13097f93e4550561","name":"WordPress is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/wordpress\/wordpress\/vulnerability\/wordpress-core-6-5-5-contributor-stored-cross-site-scripting-via-html-api-2","description":"<p>WordPress is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: WordPress<\/p><p>Link: https:\/\/wordpress.org\/news\/category\/releases\/<\/p><p>Affected Version < 6.5.5<\/p><p>Fixed in version 6.5.5 <\/p>","date":"2024-06-25"}],"impact":[]},{"uuid":"632018b1a1f4c459c07f929190f53901587c13d438066734af622cb124442ec8","name":"5.8.2","description":null,"source":[{"id":"CVE-2022-4973","name":"CVE-2022-4973","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4973","description":"[en] WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that execute if the the_meta(); function is called on that page.","date":"2024-10-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1787027817"}