Debian Wordpress vulnerabilities
333 known vulnerabilities affecting debian/wordpress.
Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57
Vulnerabilities
Page 10 of 17
CVE-2024-31111P4MEDIUMCVSS 6.5fixed in wordpress 6.1.9+dfsg1-0+deb12u1 (bookworm)2024
CVE-2024-31111 [MEDIUM] CVE-2024-31111: wordpress - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through 6.0.8, from 5.9 through 5.9.9.
Scope: local
bookw
debian
CVE-2017-6816P4MEDIUMCVSS 4.9fixed in wordpress 4.7.3+dfsg-1 (bookworm)2017
CVE-2017-6816 [MEDIUM] CVE-2017-6816: wordpress - In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be delete...
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
Scope: local
bookworm: resolved (fixed in 4.7.3+dfsg-1)
bullseye: resolved (fixed in 4.7.3+dfsg-1)
forky: resolved (fixed in 4.7.3+dfsg-1)
sid: resolved (fixed in 4.7.3+dfsg-1)
trixie: resolved (fixed in 4.7.3+dfsg-1)
debian
CVE-2020-25286P4MEDIUMCVSS 5.3fixed in wordpress 5.4.2+dfsg1-1 (bookworm)2020
CVE-2020-25286 [MEDIUM] CVE-2020-25286: wordpress - In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a p...
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
Scope: local
bookworm: resolved (fixed in 5.4.2+dfsg1-1)
bullseye: resolved (fixed in 5.4.2+dfsg1-1)
forky: resolved (fixed in 5.4.2+dfsg1-1)
sid: resolved (fixed in 5.4.2+dfsg1-1)
tri
debian
CVE-2018-10102P4MEDIUMCVSS 6.1fixed in wordpress 4.9.5+dfsg1-1 (bookworm)2018
CVE-2018-10102 [MEDIUM] CVE-2018-10102: wordpress - Before WordPress 4.9.5, the version string was not escaped in the get_the_genera...
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
Scope: local
bookworm: resolved (fixed in 4.9.5+dfsg1-1)
bullseye: resolved (fixed in 4.9.5+dfsg1-1)
forky: resolved (fixed in 4.9.5+dfsg1-1)
sid: resolved (fixed in 4.9.5+dfsg1-1)
trixie: resolved (fixed in 4.9.5+dfsg1-1)
debian
CVE-2023-5692P4MEDIUMCVSS 5.3fixed in wordpress 6.5+dfsg1-1 (forky)2023
CVE-2023-5692 [MEDIUM] CVE-2023-5692: wordpress - WordPress Core is vulnerable to Sensitive Information Exposure in versions up to...
WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 6.5+df
debian
CVE-2013-2202P4MEDIUMCVSS 4.3fixed in wordpress 3.5.2+dfsg-1 (bookworm)2013
CVE-2013-2202 [MEDIUM] CVE-2013-2202: wordpress - WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oE...
WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Scope: local
bookworm: resolved (fixed in 3.5.2+dfsg-1)
bullseye: resolved (fixed in 3.5.2+dfsg-1)
forky: resolved (fixed in 3.5.
debian
CVE-2015-5623P4MEDIUMCVSS 4.0fixed in wordpress 4.2.3+dfsg-1 (bookworm)2015
CVE-2015-5623 [MEDIUM] CVE-2015-5623: wordpress - WordPress before 4.2.3 does not properly verify the edit_posts capability, which...
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.
Scope: local
bookworm: resolved (fixed in 4.2.3+dfsg-1)
bullseye: resolved (fixed in 4.2
debian
CVE-2017-6815P4MEDIUMCVSS 6.1fixed in wordpress 4.7.3+dfsg-1 (bookworm)2017
CVE-2017-6815 [MEDIUM] CVE-2017-6815: wordpress - In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can tr...
In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.
Scope: local
bookworm: resolved (fixed in 4.7.3+dfsg-1)
bullseye: resolved (fixed in 4.7.3+dfsg-1)
forky: resolved (fixed in 4.7.3+dfsg-1)
sid: resolved (fixed in 4.7.3+dfsg-1)
trixie: resolved (fixed in 4.7.3+dfsg-1)
debian
CVE-2006-5705P4MEDIUMCVSS 6.0fixed in wordpress 2.0.5-0.1 (bookworm)2006
CVE-2006-5705 [MEDIUM] CVE-2006-5705: wordpress - Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in Word...
Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters in a GET request.
Scope: local
bookworm: resolved (fixed in 2.0.5-0.1)
bullseye: resolved (fixed in 2.0.5-0.1)
forky:
debian
CVE-2019-16222P4MEDIUMCVSS 6.1fixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16222 [MEDIUM] CVE-2019-16222: wordpress - WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protoco...
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
Scope: local
bookworm: resolved (fixed in 5.2.3+dfsg1-1)
bullseye: resolved (fixed in 5.2.3+dfsg1-1)
forky: resolved (fixed in 5.2.3+dfsg1-1)
sid: resolved (fixed in 5.2.3+dfsg1-1)
trixie: resolved (f
debian
CVE-2016-5834P4MEDIUMCVSS 6.1fixed in wordpress 4.5.3+dfsg-1 (bookworm)2016
CVE-2016-5834 [MEDIUM] CVE-2016-5834: wordpress - Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function ...
Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.
Scope: local
bookworm: resolved (fixed in 4.5.3+dfsg-1)
bullseye: resolved (fixed in 4.
debian
CVE-2007-0539P4LOWCVSS 7.8fixed in wordpress 2.1.0-1 (bookworm)2007
CVE-2007-0539 [HIGH] CVE-2007-0539: wordpress - The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to ...
The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.
Scope: local
bookworm: resolved (fixed in 2.1.0-1)
bullseye: resolved (fixed in
debian
CVE-2017-6814P4MEDIUMCVSS 5.4fixed in wordpress 4.7.3+dfsg-1 (bookworm)2017
CVE-2017-6814 [MEDIUM] CVE-2017-6814: wordpress - In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via...
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.
Scope: local
b
debian
CVE-2012-2402P4MEDIUMCVSS 5.5fixed in wordpress 3.3.2+dfsg-1 (bookworm)2012
CVE-2012-2402 [MEDIUM] CVE-2012-2402: wordpress - wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site ...
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 3.3.2+dfsg-1)
bullseye: resolved (fixed in 3.3.2+dfsg-1)
forky: resolved (fixed in 3.3.2+dfsg-1)
sid: resolved (fixed in 3.3.2+df
debian
CVE-2022-43497P4MEDIUMCVSS 6.1fixed in wordpress 6.0.3+dfsg1-1 (bookworm)2022
CVE-2022-43497 [MEDIUM] CVE-2022-43497: wordpress - Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a...
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
Scope: local
bookworm: resolved (fixed in 6.0.3+dfsg1-1)
bullseye: resolved (fixed in 5.7.8+dfsg1-0+deb11u1)
forky: resolved (fixed in 6.0.3+df
debian
CVE-2020-11025P4MEDIUMCVSS 5.8fixed in wordpress 5.4.1+dfsg1-1 (bookworm)2020
CVE-2020-11025 [MEDIUM] CVE-2020-11025: wordpress - In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in...
In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4
debian
CVE-2022-43500P4MEDIUMCVSS 6.1fixed in wordpress 6.0.3+dfsg1-1 (bookworm)2022
CVE-2022-43500 [MEDIUM] CVE-2022-43500: wordpress - Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a...
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
Scope: local
bookworm: resolved (fixed in 6.0.3+dfsg1-1)
bullseye: resolved (fixed in 5.7.8+dfsg1-0+deb11u1)
forky: resolved (fixed in 6.0.3+df
debian
CVE-2018-10100P4MEDIUMCVSS 6.1fixed in wordpress 4.9.5+dfsg1-1 (bookworm)2018
CVE-2018-10100 [MEDIUM] CVE-2018-10100: wordpress - Before WordPress 4.9.5, the redirection URL for the login page was not validated...
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
Scope: local
bookworm: resolved (fixed in 4.9.5+dfsg1-1)
bullseye: resolved (fixed in 4.9.5+dfsg1-1)
forky: resolved (fixed in 4.9.5+dfsg1-1)
sid: resolved (fixed in 4.9.5+dfsg1-1)
trixie: resolved (fixed in 4.9.5+dfsg1-1)
debian
CVE-2017-6818P4MEDIUMCVSS 6.1fixed in wordpress 4.7.3+dfsg-1 (bookworm)2017
CVE-2017-6818 [MEDIUM] CVE-2017-6818: wordpress - In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripti...
In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
Scope: local
bookworm: resolved (fixed in 4.7.3+dfsg-1)
bullseye: resolved (fixed in 4.7.3+dfsg-1)
forky: resolved (fixed in 4.7.3+dfsg-1)
sid: resolved (fixed in 4.7.3+dfsg-1)
trixie: resolved (fixed in 4.7.3+dfsg-1)
debian
CVE-2012-4448P4LOWCVSS 6.8fixed in wordpress 3.5.1+dfsg-2 (bookworm)2012
CVE-2012-4448 [MEDIUM] CVE-2012-4448: wordpress - Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPre...
Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.
Scope: local
bookworm: resolved (fixed in 3.5.1+dfsg-2)
bullseye: resolved (fixed in 3.5.1+dfsg-2)
forky: resolved (fixed in 3
debian