CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
55645 | CVE-2012-2402 | Candidate | wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors. | Assigned (20120421) | None (candidate not yet proposed) | View | |
35812 | CVE-2008-5695 | Candidate | wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script"s pathname to active_plugins. | Assigned (20081219) | None (candidate not yet proposed) | View | |
59877 | CVE-2012-6634 | Candidate | wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value. | Assigned (20140120) | None (candidate not yet proposed) | View | |
64287 | CVE-2013-4340 | Candidate | wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter. | Assigned (20130612) | None (candidate not yet proposed) | View | |
102430 | CVE-2017-5610 | Candidate | wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms. | Assigned (20170128) | None (candidate not yet proposed) | View |
Page 138 of 20943, showing 5 records out of 104715 total, starting on record 686, ending on 690