CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
73529 | CVE-2014-6230 | Candidate | WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header. | Assigned (20140904) | None (candidate not yet proposed) | View | |
22120 | CVE-2006-6016 | Candidate | wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter. | Assigned (20061121) | None (candidate not yet proposed) | View | |
36884 | CVE-2008-6767 | Candidate | wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request. | Assigned (20090428) | None (candidate not yet proposed) | View | |
53182 | CVE-2011-5270 | Candidate | wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role. | Assigned (20140120) | None (candidate not yet proposed) | View | |
57665 | CVE-2012-4422 | Candidate | wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role. | Assigned (20120821) | None (candidate not yet proposed) | View |
Page 137 of 20943, showing 5 records out of 104715 total, starting on record 681, ending on 685