Debian Wordpress vulnerabilities
360 known vulnerabilities affecting debian/wordpress.
Total CVEs
360
CISA KEV
0
Public exploits
67
Exploited in wild
3
Severity breakdown
CRITICAL21HIGH56MEDIUM201LOW82
Vulnerabilities
Page 4 of 18
CVE-2019-17673HIGHCVSS 7.5fixed in wordpress 5.2.4+dfsg1-1 (bookworm)2019
CVE-2019-17673 [HIGH] CVE-2019-17673: wordpress - WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET reque...
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
Scope: local
bookworm: resolved (fixed in 5.2.4+dfsg1-1)
bullseye: resolved (fixed in 5.2.4+dfsg1-1)
forky: resolved (fixed in 5.2.4+dfsg1-1)
sid: resolved (fixed in 5.2.4+dfsg1-1)
trixie: resolved (fixed in 5.2.4+dfsg1-1)
debian
CVE-2019-17672MEDIUMCVSS 6.1fixed in wordpress 5.2.4+dfsg1-1 (bookworm)2019
CVE-2019-17672 [MEDIUM] CVE-2019-17672: wordpress - WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript...
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
Scope: local
bookworm: resolved (fixed in 5.2.4+dfsg1-1)
bullseye: resolved (fixed in 5.2.4+dfsg1-1)
forky: resolved (fixed in 5.2.4+dfsg1-1)
sid: resolved (fixed in 5.2.4+dfsg1-1)
trixie: resolved (fixed in 5.2.4+dfsg1-1)
debian
CVE-2019-16222MEDIUMCVSS 6.1fixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16222 [MEDIUM] CVE-2019-16222: wordpress - WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protoco...
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
Scope: local
bookworm: resolved (fixed in 5.2.3+dfsg1-1)
bullseye: resolved (fixed in 5.2.3+dfsg1-1)
forky: resolved (fixed in 5.2.3+dfsg1-1)
sid: resolved (fixed in 5.2.3+dfsg1-1)
trixie: resolved (f
debian
CVE-2019-16780MEDIUMCVSS 5.8fixed in wordpress 5.3.2+dfsg1-1 (bookworm)2019
CVE-2019-16780 [MEDIUM] CVE-2019-16780: wordpress - WordPress users with lower privileges (like contributors) can inject JavaScript ...
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in WordPress 5.3.1, along with all the previous
debian
CVE-2019-20042MEDIUMCVSS 6.1fixed in wordpress 5.3.2+dfsg1-1 (bookworm)2019
CVE-2019-20042 [MEDIUM] CVE-2019-20042: wordpress - In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targete...
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
Scope: local
bookworm: resolved (fixed in 5.3.2+d
debian
CVE-2019-16217MEDIUMCVSS 6.1fixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16217 [MEDIUM] CVE-2019-16217: wordpress - WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attach...
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
Scope: local
bookworm: resolved (fixed in 5.2.3+dfsg1-1)
bullseye: resolved (fixed in 5.2.3+dfsg1-1)
forky: resolved (fixed in 5.2.3+dfsg1-1)
sid: resolved (fixed in 5.2.3+dfsg1-1)
trixie: resolved (fixed in 5.2.3+dfsg1-1)
debian
CVE-2019-20043MEDIUMCVSS 4.3fixed in wordpress 5.3.2+dfsg1-1 (bookworm)2019
CVE-2019-20043 [MEDIUM] CVE-2019-20043: wordpress - In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordP...
In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3
debian
CVE-2019-17671MEDIUMCVSS 5.3PoCfixed in wordpress 5.2.4+dfsg1-1 (bookworm)2019
CVE-2019-17671 [MEDIUM] CVE-2019-17671: wordpress - In WordPress before 5.2.4, unauthenticated viewing of certain content is possibl...
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
Scope: local
bookworm: resolved (fixed in 5.2.4+dfsg1-1)
bullseye: resolved (fixed in 5.2.4+dfsg1-1)
forky: resolved (fixed in 5.2.4+dfsg1-1)
sid: resolved (fixed in 5.2.4+dfsg1-1)
trixie: resolved (fixed in 5.2.4+dfsg1-1)
debian
CVE-2019-8943MEDIUMCVSS 6.5PoC2019
CVE-2019-8943 [MEDIUM] CVE-2019-8943: wordpress - WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (w...
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.
Scope: local
bookworm: undetermined
bullseye: undetermined
forky
debian
CVE-2019-16781MEDIUMCVSS 5.8fixed in wordpress 5.3.2+dfsg1-1 (bookworm)2019
CVE-2019-16781 [MEDIUM] CVE-2019-16781: wordpress - In WordPress before 5.3.1, authenticated users with lower privileges (like contr...
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.
Scope: local
bookworm: resolved (fixed in 5.3.2+dfsg1-1)
bullseye: resolved (fixed in 5.3.2+dfsg1-1)
forky:
debian
CVE-2019-16223MEDIUMCVSS 5.4PoCfixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16223 [MEDIUM] CVE-2019-16223: wordpress - WordPress before 5.2.3 allows XSS in post previews by authenticated users.
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
Scope: local
bookworm: resolved (fixed in 5.2.3+dfsg1-1)
bullseye: resolved (fixed in 5.2.3+dfsg1-1)
forky: resolved (fixed in 5.2.3+dfsg1-1)
sid: resolved (fixed in 5.2.3+dfsg1-1)
trixie: resolved (fixed in 5.2.3+dfsg1-1)
debian
CVE-2019-16221MEDIUMCVSS 6.1fixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16221 [MEDIUM] CVE-2019-16221: wordpress - WordPress before 5.2.3 allows reflected XSS in the dashboard.
WordPress before 5.2.3 allows reflected XSS in the dashboard.
Scope: local
bookworm: resolved (fixed in 5.2.3+dfsg1-1)
bullseye: resolved (fixed in 5.2.3+dfsg1-1)
forky: resolved (fixed in 5.2.3+dfsg1-1)
sid: resolved (fixed in 5.2.3+dfsg1-1)
trixie: resolved (fixed in 5.2.3+dfsg1-1)
debian
CVE-2019-16218MEDIUMCVSS 6.1fixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16218 [MEDIUM] CVE-2019-16218: wordpress - WordPress before 5.2.3 allows XSS in stored comments.
WordPress before 5.2.3 allows XSS in stored comments.
Scope: local
bookworm: resolved (fixed in 5.2.3+dfsg1-1)
bullseye: resolved (fixed in 5.2.3+dfsg1-1)
forky: resolved (fixed in 5.2.3+dfsg1-1)
sid: resolved (fixed in 5.2.3+dfsg1-1)
trixie: resolved (fixed in 5.2.3+dfsg1-1)
debian
CVE-2019-16219MEDIUMCVSS 6.1fixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16219 [MEDIUM] CVE-2019-16219: wordpress - WordPress before 5.2.3 allows XSS in shortcode previews.
WordPress before 5.2.3 allows XSS in shortcode previews.
Scope: local
bookworm: resolved (fixed in 5.2.3+dfsg1-1)
bullseye: resolved (fixed in 5.2.3+dfsg1-1)
forky: resolved (fixed in 5.2.3+dfsg1-1)
sid: resolved (fixed in 5.2.3+dfsg1-1)
trixie: resolved (fixed in 5.2.3+dfsg1-1)
debian
CVE-2019-16220MEDIUMCVSS 6.1fixed in wordpress 5.2.3+dfsg1-1 (bookworm)2019
CVE-2019-16220 [MEDIUM] CVE-2019-16220: wordpress - In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_r...
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
Scope: local
bookworm: resolved (fixed in 5.2.3+dfsg1-1)
bullseye: resolved (fixed in 5.2.3+dfsg1-1)
forky: resolved (fixed in 5.2.3+dfsg1-1)
sid: resolved
debian
CVE-2019-17674MEDIUMCVSS 5.4fixed in wordpress 5.2.4+dfsg1-1 (bookworm)2019
CVE-2019-17674 [MEDIUM] CVE-2019-17674: wordpress - WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via th...
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
Scope: local
bookworm: resolved (fixed in 5.2.4+dfsg1-1)
bullseye: resolved (fixed in 5.2.4+dfsg1-1)
forky: resolved (fixed in 5.2.4+dfsg1-1)
sid: resolved (fixed in 5.2.4+dfsg1-1)
trixie: resolved (fixed in 5.2.4+dfsg1-1)
debian
CVE-2018-20148CRITICALCVSS 9.8fixed in wordpress 5.0.1+dfsg1-1 (bookworm)2018
CVE-2018-20148 [CRITICAL] CVE-2018-20148: wordpress - In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP o...
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.
Scope: local
bookworm: resolved (fixed in 5.0.1+dfsg1-1)
bullseye: r
debian
CVE-2018-12895HIGHCVSS 8.8PoCfixed in wordpress 4.9.7+dfsg1-1 (bookworm)2018
CVE-2018-12895 [HIGH] CVE-2018-12895: wordpress - WordPress through 4.9.6 allows Author users to execute arbitrary code by leverag...
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilit
debian
CVE-2018-20151HIGHCVSS 7.5fixed in wordpress 5.0.1+dfsg1-1 (bookworm)2018
CVE-2018-20151 [HIGH] CVE-2018-20151: wordpress - In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could b...
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.
Scope: local
bookworm: resolved (fixed in 5.0.1+dfsg1-1)
bullseye: resolved (
debian
CVE-2018-20149MEDIUMCVSS 5.4fixed in wordpress 5.0.1+dfsg1-1 (bookworm)2018
CVE-2018-20149 [MEDIUM] CVE-2018-20149: wordpress - In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is u...
In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.
Scope: local
bookworm: resolved (fixed in 5.0.1+dfsg1-1)
bullseye: resolved (fixed in 5.0.1+dfsg1-1)
forky: resolved (fixed in 5.0.1+
debian