CVE List

Id CVE No. Status Description Phase Votes Comments Actions
55645  CVE-2012-2402  Candidate  wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.  Assigned (20120421)  None (candidate not yet proposed)    View
35812  CVE-2008-5695  Candidate  wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script"s pathname to active_plugins.  Assigned (20081219)  None (candidate not yet proposed)    View
59877  CVE-2012-6634  Candidate  wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.  Assigned (20140120)  None (candidate not yet proposed)    View
64287  CVE-2013-4340  Candidate  wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.  Assigned (20130612)  None (candidate not yet proposed)    View
102430  CVE-2017-5610  Candidate  wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.  Assigned (20170128)  None (candidate not yet proposed)    View

Page 138 of 20943, showing 5 records out of 104715 total, starting on record 686, ending on 690

Actions