CVE-2021-39200medium · CVSS 5.3 — WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versio
CVE-2021-39202high · CVSS 7.6 — WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versio
CVE-2021-39203medium · CVSS 6.8 — WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versio
CVE-2022-21661high · CVSS 8.0 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitizatio
CVE-2022-21662high · CVSS 8.0 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticate
CVE-2022-21663medium · CVSS 6.6 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with
CVE-2022-21664high · CVSS 7.4 — WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanit
CVE-2022-43497medium · CVSS 6.1 — Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary scri
CVE-2022-43500medium · CVSS 6.1 — Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary scri
CVE-2022-43504medium · CVSS 5.3 — Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email addr
CVE-2022-3590medium · CVSS 5.9 — WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation ch
CVE-2023-22622medium · CVSS 5.3 — WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the so
CVE-2023-2745medium · CVSS 5.4 — WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthen
CVE-2023-39999medium · CVSS 4.3 — Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1
CVE-2023-5561medium · CVSS 5.3 — WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the em
CVE-2024-31210high · CVSS 7.6 — WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plug
CVE-2022-4973medium · CVSS 4.9 — WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with acce
CVE-2011-4969medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inj
CVE-2019-11358medium · CVSS 6.1 — jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
CVE-2020-7656medium · CVSS 6.1 — jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML