Known vulnerabilities in WordPress - page 5

Software: WordPress
Software CPE: cpe:2.3:a:wordpress_org:wordpress:*:*:*:*:*:*:*:*
Total vulnerabilities: 251
Public exploits: 24
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting WordPress WordPress is affected by 251 known vulnerabilities: 3 critical, 22 high, 87 medium, 139 low Critical High Medium Low

Vulnerabilities (251)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU54394 - Incorrect Regular Expression
CVE-2020-28500
CWE-185 Medium
No
No
5.2.12, 5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1 27.06.2021 SB2021062702
SB2021062703
SB2021090905
and 30 more
#VU53202 - Command injection
CVE-2021-23337
CWE-77 Medium
No
No
5.2.12, 5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1 12.05.2021 SB2021021525
SB2021051230
SB2021062703
and 60 more
#VU52550 - Permissions, Privileges, and Access Controls
CVE-2021-29450
CWE-264 Low
No
No
4.7.20, 4.8.16, 4.9.17, 5.0.12, 5.1.9, 5.2.10, 5.3.7, 5.4.5, 5.5.4, 5.6.3, 5.7.1 25.04.2021 SB2021042553
SB2021042336
#VU52549 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2021-29447
CWE-611 Medium
Available
No
4.7.20, 4.8.16, 4.9.17, 5.0.12, 5.1.9, 5.2.10, 5.3.7, 5.4.5, 5.5.4, 5.6.3, 5.7.1 25.04.2021 SB2021042553
SB2021042336
#VU48200 - Deserialization of Untrusted Data
CVE-2020-28032
CWE-502 High
Available
No
5.5.2 02.11.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48201 - Permissions, Privileges, and Access Controls
CVE-2020-28033
CWE-264 Medium
No
No
5.5.2 02.11.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48202 - Improper Access Control
CVE-2020-28036
CWE-284 High
No
No
5.5.2 02.11.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48040 - Cross-Site Request Forgery (CSRF)
CVE-2020-28040
CWE-352 Medium
No
No
5.5.2 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48039 - Improper Access Control
CVE-2020-28039
CWE-284 Medium
No
No
5.5.2 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48038 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-28038
CWE-79 Low
Available
No
5.5.2 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48037 - Resource Management Errors
CVE-2020-28037
CWE-399 High
No
No
5.5.2 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48036 - Permissions, Privileges, and Access Controls
CVE-2020-28035
CWE-264 Medium
No
No
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.7, 5.2.8, 5.3.5, 5.4.3, 5.5.2 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48035 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-28034
CWE-79 Medium
No
No
5.5.2 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU29009 - Improper Access Control
CWE-284 Low
No
No
3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2 12.06.2020 SB2020061210
#VU29008 - Permissions, Privileges, and Access Controls
CVE-2020-4050
CWE-264 Low
No
No
3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2 12.06.2020 SB2020061210
SB2020062438
SB20200611184
and 3 more
#VU29007 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2020-4048
CWE-601 Low
No
No
3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2 12.06.2020 SB2020061210
SB2020062438
SB20200611184
and 3 more
#VU29006 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-4049
CWE-79 Low
No
No
3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2 12.06.2020 SB2020061210
SB2020062438
SB20200611184
and 3 more
#VU29005 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-4047
CWE-79 Low
No
No
3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2 12.06.2020 SB2020061210
SB2020062438
SB20200611184
and 3 more
#VU29004 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-4046
CWE-79 Low
No
No
3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2 12.06.2020 SB2020061210
SB2020062438
SB20200611184
and 3 more
#VU27438 - Weak password recovery mechanism
CVE-2020-11027
CWE-640 High
Available
No
3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1 29.04.2020 SB2020042920
SB2020050617
SB2020043039
and 1 more


Showing elements 81 - 100 out of 251