HomeWordPress vulnerabilitiesWordPress core
WordPress core vulnerabilities
WordPress core has 61 known vulnerabilities in this database. The most recent published record is dated 6 Oct 2026.
- Known vulnerabilities
- 61
- Most recent
- 6 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Sensitive data exposure CVE-2026-66666 | Medium 6.9 | Up to 6.6.9 | Check for an update | 1 d ago |
| SQL injection Exploited in the wild CVE-2026-60137 | Medium 5.9 | Before 7.0.2 | Fixed in 7.0.2 | 17 Jul 2026 |
| SQL injection Exploited in the wild CVE-2026-63030 | Critical 9.8 | Before 7.0.2 | Fixed in 7.0.2 | 17 Jul 2026 |
| Cross-site scripting (XSS) CVE-2022-50945 | Medium 6.4 | Not yet published | Check for an update | 10 May 2026 |
| Security weakness CVE-2025-54352 | Low 3.7 | Up to 6.8.2 | Check for an update | 21 Jul 2025 |
| Broken access control CVE-2023-39999 | Medium 4.3 | Up to 4.1.38 | Fixed in 6.3.2 | 13 Oct 2023 |
| Security weakness CVE-2023-22622 | Medium 5.3 | Up to 6.1.1 | Check for an update | 5 Jan 2023 |
| Security weakness CVE-2021-44223 | High 8.1 | Before 5.8 | Fixed in 5.8 | 25 Nov 2021 |
| Cross-site scripting (XSS) CVE-2020-28038 | Medium 6.1 | Before 5.5.2 | Fixed in 5.5.2 | 2 Nov 2020 |
| Cross-site request forgery (CSRF) CVE-2020-28040 | Medium 4.3 | Before 5.5.2 | Fixed in 5.5.2 | 2 Nov 2020 |
| PHP object injection CVE-2020-28032 | Critical 9.8 | Before 5.5.2 | Fixed in 5.5.2 | 2 Nov 2020 |
| Security weakness CVE-2020-28033 | High 7.5 | Before 5.5.2 | Fixed in 5.5.2 | 2 Nov 2020 |
| Cross-site scripting (XSS) CVE-2020-28034 | Medium 6.1 | Before 5.5.2 | Fixed in 5.5.2 | 2 Nov 2020 |
| Security weakness CVE-2020-28035 | Critical 9.8 | Before 5.5.2 | Fixed in 5.5.2 | 2 Nov 2020 |
| Cross-site scripting (XSS) CVE-2019-17672 | Medium 6.1 | Before 5.2.4 | Fixed in 5.2.4 | 17 Oct 2019 |
| Security weakness CVE-2019-17673 | High 7.5 | Before 5.2.4 | Fixed in 5.2.4 | 17 Oct 2019 |
| Cross-site scripting (XSS) CVE-2019-17674 | Medium 5.4 | Before 5.2.4 | Fixed in 5.2.4 | 17 Oct 2019 |
| Cross-site request forgery (CSRF) CVE-2019-17675 | High 8.8 | Before 5.2.4 | Fixed in 5.2.4 | 17 Oct 2019 |
| Server-side request forgery (SSRF) CVE-2019-17669 | Critical 9.8 | Before 5.2.4 | Fixed in 5.2.4 | 17 Oct 2019 |
| Server-side request forgery (SSRF) CVE-2019-17670 | Critical 9.8 | Before 5.2.4 | Fixed in 5.2.4 | 17 Oct 2019 |
| Cross-site scripting (XSS) CVE-2019-16221 | Medium 6.1 | Before 5.2.3 | Fixed in 5.2.3 | 11 Sep 2019 |
| Cross-site scripting (XSS) CVE-2019-16222 | Medium 6.1 | Before 5.2.3 | Fixed in 5.2.3 | 11 Sep 2019 |
| Cross-site scripting (XSS) CVE-2019-16223 | Medium 5.4 | Before 5.2.3 | Fixed in 5.2.3 | 11 Sep 2019 |
| Cross-site scripting (XSS) CVE-2019-16217 | Medium 6.1 | Before 5.2.3 | Fixed in 5.2.3 | 11 Sep 2019 |
| Cross-site scripting (XSS) CVE-2019-16218 | Medium 6.1 | Before 5.2.3 | Fixed in 5.2.3 | 11 Sep 2019 |
| Cross-site scripting (XSS) CVE-2019-16219 | Medium 6.1 | Before 5.2.3 | Fixed in 5.2.3 | 11 Sep 2019 |
| Sensitive data exposure CVE-2017-6514 | Medium 5.3 | Not yet published | Check for an update | 22 May 2019 |
| Cross-site scripting (XSS) CVE-2019-9787 | High 8.8 | Before 5.1.1 | Fixed in 5.1.1 | 14 Mar 2019 |
| Remote code execution CVE-2019-8942 | High 8.8 | Before 4.9.9 | Fixed in 4.9.9 | 20 Feb 2019 |
| Path traversal CVE-2019-8943 | Medium 6.5 | Up to 5.0.3 | Check for an update | 20 Feb 2019 |
| Remote code execution CVE-2018-1000773 | High 8.8 | Up to 4.9.8 | Check for an update | 6 Sep 2018 |
| Remote code execution CVE-2017-1000600 | High 8.8 | Before 4.9 | Fixed in 4.9 | 6 Sep 2018 |
| Path traversal CVE-2018-12895 | High 8.8 | Before 4.9.7 | Fixed in 4.9.7 | 26 Jun 2018 |
| Cross-site scripting (XSS) CVE-2018-1000556 | Medium 6.1 | Before 12.0.6 | Fixed in 12.0.6 | 26 Jun 2018 |
| Security weakness CVE-2014-6412 | High 8.1 | Before 4.4.0 | Fixed in 4.4.0 | 12 Apr 2018 |
| Cross-site scripting (XSS) CVE-2018-5776 | Medium 6.1 | Before 4.9.2 | Fixed in 4.9.2 | 18 Jan 2018 |
| SQL injection CVE-2017-16510 | Critical 9.8 | Up to 4.8.2 | Check for an update | 2 Nov 2017 |
| Security weakness CVE-2012-6707 | High 7.5 | Up to 4.8.2 | Check for an update | 19 Oct 2017 |
| Security weakness CVE-2016-9263 | Medium 4.7 | Up to 4.8.2 | Check for an update | 12 Oct 2017 |
| SQL injection CVE-2017-14990 | Medium 6.5 | Not yet published | Check for an update | 3 Oct 2017 |
| Security weakness CVE-2017-8295 | Medium 5.9 | Up to 4.7.4 | Check for an update | 4 May 2017 |
| Server-side request forgery (SSRF) CVE-2016-4029 | High 8.6 | Before 4.5 | Fixed in 4.5 | 7 Aug 2016 |
| Security weakness CVE-2016-5839 | High 7.5 | Up to 4.5.2 | Check for an update | 29 Jun 2016 |
| Security weakness CVE-2016-5838 | High 7.5 | Up to 4.5.2 | Check for an update | 29 Jun 2016 |
| Security weakness CVE-2016-5837 | High 7.5 | Up to 4.5.2 | Check for an update | 29 Jun 2016 |
| Sensitive data exposure CVE-2016-5835 | High 7.5 | Up to 4.5.2 | Check for an update | 29 Jun 2016 |
| Broken access control CVE-2015-5623 | Not scored | Up to 4.2.2 | Check for an update | 3 Aug 2015 |
| Security weakness CVE-2014-9037 | Not scored | Up to 3.7.4 | Check for an update | 25 Nov 2014 |
| Security weakness CVE-2014-0165 | Not scored | Up to 3.7.1 | Check for an update | 10 Apr 2014 |
| Security weakness CVE-2010-5297 | Not scored | Up to 3.0 | Check for an update | 21 Jan 2014 |
| Security weakness CVE-2013-4339 | Not scored | Up to 3.6 | Check for an update | 12 Sep 2013 |
| Security weakness CVE-2013-2200 | Not scored | Up to 3.5.1 | Check for an update | 8 Jul 2013 |
| Sensitive data exposure CVE-2013-2202 | Not scored | Up to 3.5.1 | Check for an update | 8 Jul 2013 |
| Security weakness CVE-2013-2203 | Not scored | Up to 3.5.1 | Check for an update | 8 Jul 2013 |
| Sensitive data exposure CVE-2012-5868 | Not scored | Not yet published | Check for an update | 27 Dec 2012 |
| Security weakness CVE-2012-3385 | Not scored | Up to 3.4.0 | Check for an update | 22 Jul 2012 |
| Sensitive data exposure CVE-2011-3818 | Not scored | Not yet published | Check for an update | 24 Sep 2011 |
| Sensitive data exposure CVE-2011-3126 | Not scored | Before 3.1.3 | Fixed in 3.1.3 | 10 Aug 2011 |
| Security weakness CVE-2011-3127 | Not scored | Before 3.1.3 | Fixed in 3.1.3 | 10 Aug 2011 |
| Sensitive data exposure CVE-2011-3128 | Not scored | Before 3.1.3 | Fixed in 3.1.3 | 10 Aug 2011 |
| Security weakness CVE-2010-0682 | Not scored | Before 2.9.2 | Fixed in 2.9.2 | 23 Feb 2010 |
Read the published descriptions
- CVE-2026-66666, 6 Oct 2026
- Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data. This issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6.8.10, from 6.7 through 6.7.9, and from 6.6 through 6.6.9. CVE record
- CVE-2026-60137, 17 Jul 2026
- WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. CVE record
- CVE-2026-63030, 17 Jul 2026
- WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. CVE record
- CVE-2022-50945, 10 May 2026
- WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or dady2_input_text fields via the plugin options panel to execute arbitrary code when the page is viewed. CVE record
- CVE-2025-54352, 21 Jul 2025
- WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior. CVE record
- CVE-2023-39999, 13 Oct 2023
- Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38. CVE record
- CVE-2023-22622, 5 Jan 2023
- WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits. CVE record
- CVE-2021-44223, 25 Nov 2021
- WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory. CVE record
- CVE-2020-28038, 2 Nov 2020
- WordPress before 5.5.2 allows stored XSS via post slugs. CVE record
- CVE-2020-28040, 2 Nov 2020
- WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. CVE record
- CVE-2020-28032, 2 Nov 2020
- WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. CVE record
- CVE-2020-28033, 2 Nov 2020
- WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed. CVE record
- CVE-2020-28034, 2 Nov 2020
- WordPress before 5.5.2 allows XSS associated with global variables. CVE record
- CVE-2020-28035, 2 Nov 2020
- WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. CVE record
- CVE-2019-17672, 17 Oct 2019
- WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. CVE record
- CVE-2019-17673, 17 Oct 2019
- WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header. CVE record
- CVE-2019-17674, 17 Oct 2019
- WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer. CVE record
- CVE-2019-17675, 17 Oct 2019
- WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF. CVE record
- CVE-2019-17669, 17 Oct 2019
- WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. CVE record
- CVE-2019-17670, 17 Oct 2019
- WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs. CVE record
- CVE-2019-16221, 11 Sep 2019
- WordPress before 5.2.3 allows reflected XSS in the dashboard. CVE record
- CVE-2019-16222, 11 Sep 2019
- WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks. CVE record
- CVE-2019-16223, 11 Sep 2019
- WordPress before 5.2.3 allows XSS in post previews by authenticated users. CVE record
- CVE-2019-16217, 11 Sep 2019
- WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. CVE record
- CVE-2019-16218, 11 Sep 2019
- WordPress before 5.2.3 allows XSS in stored comments. CVE record
- CVE-2019-16219, 11 Sep 2019
- WordPress before 5.2.3 allows XSS in shortcode previews. CVE record
- CVE-2017-6514, 22 May 2019
- WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring. CVE record
- CVE-2019-9787, 14 Mar 2019
- WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php. CVE record
- CVE-2019-8942, 20 Feb 2019
- WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943. CVE record
- CVE-2019-8943, 20 Feb 2019
- WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring. CVE record
- CVE-2018-1000773, 6 Sep 2018
- WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. CVE record
- CVE-2017-1000600, 6 Sep 2018
- WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9 CVE record
- CVE-2018-12895, 26 Jun 2018
- WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges. CVE record
- CVE-2018-1000556, 26 Jun 2018
- WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing a cookie to code injection. This attack appear to be exploitable via an attacker must craft an URL with payload and send to the user. Victim need to open the link to be affected by reflected XSS. . CVE record
- CVE-2014-6412, 12 Apr 2018
- WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach. CVE record
- CVE-2018-5776, 18 Jan 2018
- WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement). CVE record
- CVE-2017-16510, 2 Nov 2017
- WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723. CVE record
- CVE-2012-6707, 19 Oct 2017
- WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions. CVE record
- CVE-2016-9263, 12 Oct 2017
- WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file. CVE record
- CVE-2017-14990, 3 Oct 2017
- WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability). CVE record
- CVE-2017-8295, 4 May 2017
- WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this message to bounce or be resent, leading to transmission of the reset key to a mailbox on an attacker-controlled SMTP server. This is related to problematic use of the SERVER_NAME variable in wp-includes/pluggable.php in conjunction with the PHP mail function. Exploitation is not achievable in all cases because it requires at least one of the following: (1) the attacker can prevent the victim from receiving any e-mail messages for an extended period of time (such as 5 days), (2) the victim's e-mail system sends an autoresponse containing the original message, or (3) the victim manually composes a reply containing the original message. CVE record
- CVE-2016-4029, 7 Aug 2016
- WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address. CVE record
- CVE-2016-5839, 29 Jun 2016
- WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors. CVE record
- CVE-2016-5838, 29 Jun 2016
- WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie. CVE record
- CVE-2016-5837, 29 Jun 2016
- WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors. CVE record
- CVE-2016-5835, 29 Jun 2016
- WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php. CVE record
- CVE-2015-5623, 3 Aug 2015
- WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php. CVE record
- CVE-2014-9037, 25 Nov 2014
- WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash. CVE record
- CVE-2014-0165, 10 Apr 2014
- WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php. CVE record
- CVE-2010-5297, 21 Jan 2014
- WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. CVE record
- CVE-2013-4339, 12 Sep 2013
- WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string. CVE record
- CVE-2013-2200, 8 Jul 2013
- WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors. CVE record
- CVE-2013-2202, 8 Jul 2013
- WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. CVE record
- CVE-2013-2203, 8 Jul 2013
- WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message. CVE record
- CVE-2012-5868, 27 Dec 2012
- WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack. CVE record
- CVE-2012-3385, 22 Jul 2012
- WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors. CVE record
- CVE-2011-3818, 24 Sep 2011
- WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files. CVE record
- CVE-2011-3126, 10 Aug 2011
- WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects. CVE record
- CVE-2011-3127, 10 Aug 2011
- WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site. CVE record
- CVE-2011-3128, 10 Aug 2011
- WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php. CVE record
- CVE-2010-0682, 23 Feb 2010
- WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter. CVE record
What to do if you run WordPress core
If you run WordPress core, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.