NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
11525 | CVE-2011-5270 | wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role. | 2 | 4 | Medium | 2017-01-07 | 2014-01-21 | View | |
45813 | CVE-2012-4422 | wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role. | 2 | 3.5 | Low | 2017-01-19 | 2012-09-17 | View | |
44213 | CVE-2012-2402 | wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors. | 2 | 5.5 | Medium | 2017-01-19 | 2012-06-28 | View | |
5437 | CVE-2008-5695 | wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script"s pathname to active_plugins. | 2 | 8.5 | High | 2017-01-03 | 2009-01-29 | View | |
47310 | CVE-2012-6634 | wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value. | 2 | 6.4 | Medium | 2017-01-19 | 2014-02-24 | View |
Page 157 of 17672, showing 5 records out of 88360 total, starting on record 781, ending on 785