Debian Wordpress vulnerabilities
360 known vulnerabilities affecting debian/wordpress.
Total CVEs
360
CISA KEV
0
Public exploits
67
Exploited in wild
3
Severity breakdown
CRITICAL21HIGH56MEDIUM201LOW82
Vulnerabilities
Page 8 of 18
CVE-2016-5838HIGHCVSS 7.5fixed in wordpress 4.5.3+dfsg-1 (bookworm)2016
CVE-2016-5838 [HIGH] CVE-2016-5838: wordpress - WordPress before 4.5.3 allows remote attackers to bypass intended password-chang...
WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.
Scope: local
bookworm: resolved (fixed in 4.5.3+dfsg-1)
bullseye: resolved (fixed in 4.5.3+dfsg-1)
forky: resolved (fixed in 4.5.3+dfsg-1)
sid: resolved (fixed in 4.5.3+dfsg-1)
trixie: resolved (fixed in 4.5.3+dfsg-1)
debian
CVE-2016-2221HIGHCVSS 7.4fixed in wordpress 4.4.2+dfsg-1 (bookworm)2016
CVE-2016-2221 [HIGH] CVE-2016-2221: wordpress - Open redirect vulnerability in the wp_validate_redirect function in wp-includes/...
Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated by an https:example.com URL.
Scope: local
bookworm: resolved (fixed in 4.4.2
debian
CVE-2016-5832HIGHCVSS 7.5fixed in wordpress 4.5.3+dfsg-1 (bookworm)2016
CVE-2016-5832 [HIGH] CVE-2016-5832: wordpress - The customizer in WordPress before 4.5.3 allows remote attackers to bypass inten...
The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.5.3+dfsg-1)
bullseye: resolved (fixed in 4.5.3+dfsg-1)
forky: resolved (fixed in 4.5.3+dfsg-1)
sid: resolved (fixed in 4.5.3+dfsg-1)
trixie: resolved (fixed in 4.5.3+dfsg-1)
debian
CVE-2016-9263MEDIUMCVSS 4.7fixed in wordpress 4.1+dfsg-1 (bookworm)2016
CVE-2016-9263 [MEDIUM] CVE-2016-9263: wordpress - WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is n...
WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.
Scope: local
bookworm: resolved (fixed in 4.1+dfsg-1)
bullseye: resolved (fixed in 4.1+dfsg-1)
forky: r
debian
CVE-2016-10148MEDIUMCVSS 4.3fixed in wordpress 4.6.1+dfsg-1 (bookworm)2016
CVE-2016-10148 [MEDIUM] CVE-2016-10148: wordpress - The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in Word...
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896.
Scope: local
bookwor
debian
CVE-2016-7169MEDIUMCVSS 6.3fixed in wordpress 4.6.1+dfsg-1 (bookworm)2016
CVE-2016-7169 [MEDIUM] CVE-2016-7169: wordpress - Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/...
Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.
Scope: local
bookworm: resolved (fixed in 4.6.1+dfsg-1)
bullseye: resolved (fixed in 4.6.1+df
debian
CVE-2016-4566MEDIUMCVSS 6.1fixed in wordpress 4.5.2+dfsg-1 (bookworm)2016
CVE-2016-4566 [MEDIUM] CVE-2016-4566: wordpress - Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload befor...
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
Scope: local
bookworm: resolved (fixed in 4.5.2+dfsg-1)
bullseye: resolved (fixed in 4.5.2+dfsg-1)
forky: resolved (fixed in 4.5.
debian
CVE-2016-5833MEDIUMCVSS 6.1fixed in wordpress 4.5.3+dfsg-1 (bookworm)2016
CVE-2016-5833 [MEDIUM] CVE-2016-5833: wordpress - Cross-site scripting (XSS) vulnerability in the column_title function in wp-admi...
Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.
Scope: local
bookworm: resolved (fixed in 4.5.3+dfsg-1)
bullseye: resolved (fix
debian
CVE-2016-7168MEDIUMCVSS 4.8fixed in wordpress 4.6.1+dfsg-1 (bookworm)2016
CVE-2016-7168 [MEDIUM] CVE-2016-7168: wordpress - Cross-site scripting (XSS) vulnerability in the media_handle_upload function in ...
Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
Scope: local
bookworm: resolved (fixed in 4.6.1+dfsg-1)
bullseye: resolved (f
debian
CVE-2016-5834MEDIUMCVSS 6.1fixed in wordpress 4.5.3+dfsg-1 (bookworm)2016
CVE-2016-5834 [MEDIUM] CVE-2016-5834: wordpress - Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function ...
Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.
Scope: local
bookworm: resolved (fixed in 4.5.3+dfsg-1)
bullseye: resolved (fixed in 4.
debian
CVE-2016-6634MEDIUMCVSS 6.1fixed in wordpress 4.5+dfsg-1 (bookworm)2016
CVE-2016-6634 [MEDIUM] CVE-2016-6634: wordpress - Cross-site scripting (XSS) vulnerability in the network settings page in WordPre...
Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.5+dfsg-1)
bullseye: resolved (fixed in 4.5+dfsg-1)
forky: resolved (fixed in 4.5+dfsg-1)
sid: resolved (fixed in 4.5+dfsg-1)
trixie: resolve
debian
CVE-2016-1564MEDIUMCVSS 6.1fixed in wordpress 4.4.1+dfsg-1 (bookworm)2016
CVE-2016-1564 [MEDIUM] CVE-2016-1564: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-them...
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.
Scope: local
bookworm: resolved (fixed in 4.4.1+dfsg-1)
bullseye: resolved (fixed in 4.4.1+dfsg-1)
forky: resolved (fi
debian
CVE-2015-2213HIGHCVSS 7.5fixed in wordpress 4.2.4+dfsg-1 (bookworm)2015
CVE-2015-2213 [HIGH] CVE-2015-2213: wordpress - SQL injection vulnerability in the wp_untrash_post_comments function in wp-inclu...
SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.
Scope: local
bookworm: resolved (fixed in 4.2.4+dfsg-1)
bullseye: resolved (fixed in 4.2.4+dfsg-1)
forky: resolved (fixed in 4
debian
CVE-2015-3439MEDIUMCVSS 4.3fixed in wordpress 4.2+dfsg-1 (bookworm)2015
CVE-2015-3439 [MEDIUM] CVE-2015-3439: wordpress - Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupl...
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as a
debian
CVE-2015-5715MEDIUMCVSS 4.3fixed in wordpress 4.3.1+dfsg-1 (bookworm)2015
CVE-2015-5715 [MEDIUM] CVE-2015-5715: wordpress - The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC...
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.3.1+dfsg-1)
bullseye: resolved (fixed in 4.3.1+
debian
CVE-2015-3429MEDIUMCVSS 4.3fixed in wordpress 4.2.2+dfsg-1 (bookworm)2015
CVE-2015-3429 [MEDIUM] CVE-2015-3429: wordpress - Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3....
Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.
Scope: local
bookworm: resolved (fixed in 4.2.2+dfsg-1)
bullseye: resolved (fixed in 4.2.2+dfsg-1)
forky: resolved (fixed in 4.2.2+dfsg-1)
sid: resolved (fi
debian
CVE-2015-5730MEDIUMCVSS 5.0fixed in wordpress 4.2.4+dfsg-1 (bookworm)2015
CVE-2015-5730 [MEDIUM] CVE-2015-5730: wordpress - The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets....
The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.
Scope: local
bookworm: resolved (fixed in 4.2.4+dfsg-1)
bullseye: resolved (f
debian
CVE-2015-8834MEDIUMCVSS 4.3fixed in wordpress 4.2.2+dfsg-1 (bookworm)2015
CVE-2015-8834 [MEDIUM] CVE-2015-8834: wordpress - Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress b...
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3440.
Scope: local
bookworm: resolved (f
debian
CVE-2015-5733MEDIUMCVSS 4.3fixed in wordpress 4.2.4+dfsg-1 (bookworm)2015
CVE-2015-5733 [MEDIUM] CVE-2015-5733: wordpress - Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfIt...
Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.
Scope: local
bookworm: resolved (fixed in 4.2.4+dfsg-1)
bullseye: resolved (fixed in 4.2.4+dfsg-1)
forky: resolved (fixed i
debian
CVE-2015-7989MEDIUMCVSS 6.1fixed in wordpress 4.3.1+dfsg-1 (bookworm)2015
CVE-2015-7989 [MEDIUM] CVE-2015-7989: wordpress - Cross-site scripting (XSS) vulnerability in the user list table in WordPress bef...
Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.
Scope: local
bookworm: resolved (fixed in 4.3.1+dfsg-1)
bullseye: resolved (fixed in 4.3.1+dfsg-1)
forky: resolved (fixed in 4.
debian