Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
wordpress wordpress 1.3.1 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-4671
Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address parameters....
Wordpress Wordpress Mu 1.3.1
Wordpress Wordpress Mu 1.3
Wordpress Wordpress Mu 1.2.3
Wordpress Wordpress Mu 1.2.2
Wordpress Wordpress Mu 1.0
Wordpress Wordpress Mu
1 EDB exploit available
NA
CVE-2009-1030
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header....
Wordpress Wordpress Mu 1.0
Wordpress Wordpress Mu 1.2.4
Wordpress Wordpress Mu 1.2.5a
Wordpress Wordpress Mu 2.6.3
Wordpress Wordpress Mu 2.6.5
Wordpress Wordpress Mu 1.2.2
Wordpress Wordpress Mu 1.1.1
Wordpress Wordpress Mu 1.1
Wordpress Wordpress Mu 1.5
Wordpress Wordpress Mu 1.5.1
Wordpress Wordpress Mu 1.3
Wordpress Wordpress Mu 1.2.3
Wordpress Wordpress Mu 1.3.2
Wordpress Wordpress Mu 1.3.3
Wordpress Wordpress Mu 2.7
Wordpress Wordpress Mu
Wordpress Wordpress Mu 1.3.1
Wordpress Wordpress Mu 1.2
Wordpress Wordpress Mu 1.2.1
Wordpress Wordpress Mu 2.6.1
Wordpress Wordpress Mu 2.6.2
1 EDB exploit available
NA
CVE-2008-2146
wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages....
Wordpress Wordpress 0.6.2
Wordpress Wordpress 0.6.2.1
Wordpress Wordpress 1.2
Wordpress Wordpress 1.2.1
Wordpress Wordpress 1.5.1.1
Wordpress Wordpress 1.5.1.2
Wordpress Wordpress 2.0.10 Rc2
Wordpress Wordpress 2.0.11
Wordpress Wordpress 2.0.8
Wordpress Wordpress 2.0.9
Wordpress Wordpress 2.2
Wordpress Wordpress 2.2.0
Wordpress Wordpress 1.0.1
Wordpress Wordpress 1.0.2
Wordpress Wordpress 1.5-strayhorn
Wordpress Wordpress 1.5.1
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.0.10
Wordpress Wordpress 2.0.10 Rc1
Wordpress Wordpress 2.0.6
Wordpress Wordpress 2.0.7
Wordpress Wordpress 2.1.3 Rc1
Wordpress Wordpress 2.1.3 Rc2
Wordpress Wordpress 0.7
Wordpress Wordpress 0.71
Wordpress Wordpress 1.2.2
Wordpress Wordpress 1.3.1
Wordpress Wordpress 1.5.1.3
Wordpress Wordpress 1.5.2
Wordpress Wordpress 2.0.2
Wordpress Wordpress 2.0.3
Wordpress Wordpress 2.1
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.2.1
Wordpress Wordpress 2.2 Revision5002
Wordpress Wordpress 0.711
Wordpress Wordpress 1.0
Wordpress Wordpress 1.4
Wordpress Wordpress 1.5
Wordpress Wordpress 1.6
Wordpress Wordpress 2.0
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.0.5
Wordpress Wordpress 2.1.2
Wordpress Wordpress 2.1.3
Wordpress Wordpress 2.2 Revision5003
Wordpress Wordpress
NA
CVE-2009-2334
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify...
Wordpress Wordpress 2.3.3
Wordpress Wordpress 2.3.2
Wordpress Wordpress 2.2.2
Wordpress Wordpress 2.2.1
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.1
Wordpress Wordpress 2.6
Wordpress Wordpress 2.3.1
Wordpress Wordpress 2.2.0
Wordpress Wordpress 2.2
Wordpress Wordpress 2.0.9
Wordpress Wordpress 2.0.8
Wordpress Wordpress 2.0.11
Wordpress Wordpress 2.0.10 Rc2
Wordpress Wordpress 1.5.1.3
Wordpress Wordpress 1.5.1.2
Wordpress Wordpress 1.2.2
Wordpress Wordpress 1.2.1
Wordpress Wordpress 2.5.1
Wordpress Wordpress 2.5
Wordpress Wordpress 2.3
Wordpress Wordpress 2.2 Revision5003
Wordpress Wordpress 2.1.3 Rc2
Wordpress Wordpress 2.1.3 Rc1
Wordpress Wordpress 2.0.7
Wordpress Wordpress 2.0.6
Wordpress Wordpress 2.0.10 Rc1
Wordpress Wordpress 2.0.10
Wordpress Wordpress 1.5.1.1
Wordpress Wordpress 1.5.1
Wordpress Wordpress 1.5-strayhorn
Wordpress Wordpress 1.2-mingus
Wordpress Wordpress 1.2-delta
Wordpress Wordpress 1.0.2
Wordpress Wordpress 1.0.1-miles
Wordpress Wordpress 0.711
Wordpress Wordpress 0.71-gold
Wordpress Wordpress 2.6.1
Wordpress Wordpress 2.6.3
Wordpress Wordpress Mu 1.2.4
Wordpress Wordpress Mu 2.6
Wordpress Wordpress Mu 2.6.1
Wordpress Wordpress 2.0.3
Wordpress Wordpress 2.0.2
Wordpress Wordpress 1.6
Wordpress Wordpress 1.5.2
Wordpress Wordpress 1.3.1
Wordpress Wordpress 1.2
Wordpress Wordpress 1.0
Wordpress Wordpress 0.72
Wordpress Wordpress 0.6.2
Wordpress Wordpress 0.6.2.1
Wordpress Wordpress Mu 1.2
Wordpress Wordpress Mu 1.2.1
Wordpress Wordpress Mu 1.3.1
Wordpress Wordpress Mu 1.3.2
Wordpress Wordpress Mu 1.3.3
Wordpress Wordpress Mu 2.6.5
Wordpress Wordpress Mu
Wordpress Wordpress 1.0.2-blakey
Wordpress Wordpress Mu 1.2.2
Wordpress Wordpress Mu 1.2.3
Wordpress Wordpress Mu 1.5.1
Wordpress Wordpress Mu 1.5
Wordpress Wordpress
Wordpress Wordpress 2.6.5
Wordpress Wordpress 2.2 Revision5002
Wordpress Wordpress 2.2.3
Wordpress Wordpress 2.1.3
Wordpress Wordpress 2.1.2
Wordpress Wordpress 2.0.5
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.0
Wordpress Wordpress 1.5
Wordpress Wordpress 1.4
Wordpress Wordpress 1.0.1
Wordpress Wordpress 1.0-platinum
Wordpress Wordpress 0.71
Wordpress Wordpress 0.7
Wordpress Wordpress Mu 1.1
Wordpress Wordpress Mu 1.1.1
Wordpress Wordpress Mu 1.2.5a
Wordpress Wordpress Mu 1.3
Wordpress Wordpress Mu 2.6.2
Wordpress Wordpress Mu 2.6.3
1 EDB exploit available
NA
CVE-2008-3233
Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors....
Wordpress Wordpress 1.0
Wordpress Wordpress 1.0.1
Wordpress Wordpress 1.0.2
Wordpress Wordpress 1.2
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.0.10
Wordpress Wordpress 2.0.10 Rc1
Wordpress Wordpress 2.0.10 Rc2
Wordpress Wordpress 2.1.3 Rc1
Wordpress Wordpress 2.1.3 Rc2
Wordpress Wordpress 2.2
Wordpress Wordpress 2.2.0
Wordpress Wordpress 0.7
Wordpress Wordpress 0.711
Wordpress Wordpress 1.2.1
Wordpress Wordpress 1.3.1
Wordpress Wordpress 1.5
Wordpress Wordpress 1.5.1.3
Wordpress Wordpress 1.6
Wordpress Wordpress 2.0.2
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.0.9
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.1.3
Wordpress Wordpress 2.2.1
Wordpress Wordpress 2.2.3
Wordpress Wordpress 2.5
Wordpress Wordpress 0.6.2
Wordpress Wordpress 1.5-strayhorn
Wordpress Wordpress 1.5.1
Wordpress Wordpress 1.5.1.1
Wordpress Wordpress 1.5.1.2
Wordpress Wordpress 2.0.5
Wordpress Wordpress 2.0.6
Wordpress Wordpress 2.0.7
Wordpress Wordpress 2.0.8
Wordpress Wordpress 2.2 Revision5003
Wordpress Wordpress 2.3
Wordpress Wordpress 2.3.1
Wordpress Wordpress 2.3.2
Wordpress Wordpress 0.6.2.1
Wordpress Wordpress 0.71
Wordpress Wordpress 1.2.2
Wordpress Wordpress 1.4
Wordpress Wordpress 1.5.2
Wordpress Wordpress 2.0
Wordpress Wordpress 2.0.11
Wordpress Wordpress 2.0.3
Wordpress Wordpress 2.1
Wordpress Wordpress 2.1.2
Wordpress Wordpress 2.2.2
Wordpress Wordpress 2.2 Revision5002
Wordpress Wordpress 2.3.3
Wordpress Wordpress
1 EDB exploit available
NA
CVE-2008-0664
The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors....
Wordpress Wordpress 1.5
Wordpress Wordpress 1.5.1
Wordpress Wordpress 2.0.10 Rc2
Wordpress Wordpress 2.0.11
Wordpress Wordpress 2.1
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.2.2
Wordpress Wordpress 2.2.3
Wordpress Wordpress 1.2.2
Wordpress Wordpress 1.3.1
Wordpress Wordpress 2.0.10
Wordpress Wordpress 2.0.10 Rc1
Wordpress Wordpress 2.0.6
Wordpress Wordpress 2.0.7
Wordpress Wordpress 2.2
Wordpress Wordpress 2.2.1
Wordpress Wordpress 1.2
Wordpress Wordpress 1.2.1
Wordpress Wordpress 1.5.2
Wordpress Wordpress 2.0
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.0.5
Wordpress Wordpress 2.1.3 Rc1
Wordpress Wordpress 2.1.3 Rc2
Wordpress Wordpress 2.3.1
Wordpress Wordpress 2.3.2
Wordpress Wordpress 0.7
Wordpress Wordpress 0.71
Wordpress Wordpress 1.5.1.2
Wordpress Wordpress 1.5.1.3
Wordpress Wordpress 2.0.2
Wordpress Wordpress 2.0.3
Wordpress Wordpress 2.1.2
Wordpress Wordpress 2.1.3
Wordpress Wordpress 2.2 Revision5002
Wordpress Wordpress 2.2 Revision5003
Wordpress Wordpress 2.3
NA
CVE-2009-2432
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message....
Wordpress Wordpress 2.6
Wordpress Wordpress 2.5.1
Wordpress Wordpress 2.3
Wordpress Wordpress 2.2 Revision5003
Wordpress Wordpress 2.1
Wordpress Wordpress 2.1.3 Rc2
Wordpress Wordpress 2.0.8
Wordpress Wordpress 2.0.7
Wordpress Wordpress 2.0.10 Rc1
Wordpress Wordpress 2.0.10
Wordpress Wordpress 1.5.1.1
Wordpress Wordpress 1.5.1
Wordpress Wordpress 1.2.1
Wordpress Wordpress 1.2-mingus
Wordpress Wordpress 1.0.2
Wordpress Wordpress 1.0.1-miles
Wordpress Wordpress 0.72
Wordpress Wordpress 0.711
Wordpress Wordpress 0.6.2
Wordpress Wordpress 2.6.1
Wordpress Wordpress 2.6.3
Wordpress Wordpress Mu 1.2.4
Wordpress Wordpress Mu 1.5
Wordpress Wordpress Mu 2.6
Wordpress Wordpress 2.3.3
Wordpress Wordpress 2.3.2
Wordpress Wordpress 2.2.2
Wordpress Wordpress 2.2.1
Wordpress Wordpress 2.1.2
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.0.3
Wordpress Wordpress 2.0.2
Wordpress Wordpress 1.6
Wordpress Wordpress 1.5.2
Wordpress Wordpress 1.4
Wordpress Wordpress 1.3.1
Wordpress Wordpress 1.0
Wordpress Wordpress 0.7
Wordpress Wordpress Mu 1.2
Wordpress Wordpress 2.5
Wordpress Wordpress 2.2 Revision5002
Wordpress Wordpress 2.2.3
Wordpress Wordpress 2.1.3 Rc1
Wordpress Wordpress 2.1.3
Wordpress Wordpress 2.0.6
Wordpress Wordpress 2.0.5
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.0
Wordpress Wordpress 1.5-strayhorn
Wordpress Wordpress 1.5
Wordpress Wordpress 1.2-delta
Wordpress Wordpress 1.2
Wordpress Wordpress 1.0.1
Wordpress Wordpress 1.0-platinum
Wordpress Wordpress 0.71-gold
Wordpress Wordpress 0.71
Wordpress Wordpress Mu 1.1
Wordpress Wordpress Mu 1.1.1
Wordpress Wordpress Mu 1.2.5a
Wordpress Wordpress Mu 1.3
Wordpress Wordpress Mu 2.6.1
Wordpress Wordpress Mu 2.6.2
Wordpress Wordpress Mu 1.2.1
Wordpress Wordpress Mu 1.3.1
Wordpress Wordpress Mu 1.3.2
Wordpress Wordpress Mu 2.6.3
Wordpress Wordpress Mu 2.6.5
Wordpress Wordpress 2.3.1
Wordpress Wordpress 2.2.0
Wordpress Wordpress 2.2
Wordpress Wordpress 2.0.9
Wordpress Wordpress 2.0.11
Wordpress Wordpress 2.0.10 Rc2
Wordpress Wordpress 1.5.1.3
Wordpress Wordpress 1.5.1.2
Wordpress Wordpress 1.2.2
Wordpress Wordpress 1.0.2-blakey
Wordpress Wordpress 0.6.2.1
Wordpress Wordpress Mu 1.2.2
Wordpress Wordpress Mu 1.2.3
Wordpress Wordpress Mu 1.3.3
Wordpress Wordpress Mu 1.5.1
Wordpress Wordpress Mu
Wordpress Wordpress
Wordpress Wordpress 2.6.5
NA
CVE-2008-5278
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable)....
Wordpress Wordpress 2.3
Wordpress Wordpress 2.2 Revision5003
Wordpress Wordpress 2.1.3 Rc1
Wordpress Wordpress 2.1.3
Wordpress Wordpress 2.1
Wordpress Wordpress 2.0.8
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.0.10
Wordpress Wordpress 1.2.1
Wordpress Wordpress 1.2.2
Wordpress Wordpress 1.0-platinum
Wordpress Wordpress 1.0.2-blakey
Wordpress Wordpress 0.6.2.1
Wordpress Wordpress 0.6.2
Wordpress Wordpress 0.72
Wordpress Wordpress 2.5
Wordpress Wordpress 2.5.1
Wordpress Wordpress 2.3.1
Wordpress Wordpress 2.2.2
Wordpress Wordpress 2.2.1
Wordpress Wordpress 2.2.0
Wordpress Wordpress 2.0.6
Wordpress Wordpress 2.0.7
Wordpress Wordpress 1.5.2
Wordpress Wordpress 2.0
Wordpress Wordpress 1.5.1.2
Wordpress Wordpress 1.5.1
Wordpress Wordpress 1.2-mingus
Wordpress Wordpress 1.2-delta
Wordpress Wordpress 1.0.1
Wordpress Wordpress 0.71
Wordpress Wordpress 2.3.2
Wordpress Wordpress 2.3.3
Wordpress Wordpress 2.1.3 Rc2
Wordpress Wordpress 2.2.3
Wordpress Wordpress 2.0.9
Wordpress Wordpress 2.0.3
Wordpress Wordpress 2.1.2
Wordpress Wordpress 2.0.10 Rc2
Wordpress Wordpress 2.0.10 Rc1
Wordpress Wordpress 1.6
Wordpress Wordpress 1.5-strayhorn
Wordpress Wordpress 1.5.1.1
Wordpress Wordpress 1.0.1-miles
Wordpress Wordpress 1.0.2
Wordpress Wordpress 0.71-gold
Wordpress Wordpress 0.711
Wordpress Wordpress
Wordpress Wordpress 2.6.1
Wordpress Wordpress 2.6
Wordpress Wordpress 2.2 Revision5002
Wordpress Wordpress 2.2
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.0.5
Wordpress Wordpress 2.0.11
Wordpress Wordpress 1.5.1.3
Wordpress Wordpress 2.0.2
Wordpress Wordpress 1.3.1
Wordpress Wordpress 1.5
Wordpress Wordpress 1.4
Wordpress Wordpress 1.2
Wordpress Wordpress 1.0
Wordpress Wordpress 0.7
NA
CVE-2008-4769
Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details...
Wordpress Wordpress 1.2-delta
Wordpress Wordpress 2.1.3
Wordpress Wordpress 1.0.1-miles
Wordpress Wordpress 1.5-strayhorn
Wordpress Wordpress 1.5.1.2
Wordpress Wordpress 1.5.1.3
Wordpress Wordpress 2.0.2
Wordpress Wordpress 2.0.3
Wordpress Wordpress 2.0.4
Wordpress Wordpress 2.3
Wordpress Wordpress 1.2
Wordpress Wordpress 2.2 Revision5003
Wordpress Wordpress 2.2.2
Wordpress Wordpress 1.0
Wordpress Wordpress 1.0.1
Wordpress Wordpress 0.7
Wordpress Wordpress 0.72
Wordpress Wordpress 1.4
Wordpress Wordpress 1.2-mingus
Wordpress Wordpress 2.2 Revision5002
Wordpress Wordpress 1.0.2-blakey
Wordpress Wordpress 1.5.1.1
Wordpress Wordpress 2.2.0
Wordpress Wordpress 2.3.2
Wordpress Wordpress 2.0.1
Wordpress Wordpress 2.0.7
Wordpress Wordpress 2.1
Wordpress Wordpress 2.3.1
Wordpress Wordpress 1.2.1
Wordpress Wordpress 1.2.2
Wordpress Wordpress 0.6.2.1
Wordpress Wordpress
Wordpress Wordpress 2.5
Wordpress Wordpress 2.0.11
Wordpress Wordpress 2.1.3 Rc1
Wordpress Wordpress 2.0.9
Wordpress Wordpress 2.2
Wordpress Wordpress 1.3.1
Wordpress Wordpress 2.0.10
Wordpress Wordpress 2.0.10 Rc1
Wordpress Wordpress 2.1.1
Wordpress Wordpress 2.1.2
Wordpress Wordpress 2.0.10 Rc2
Wordpress Wordpress 2.1.3 Rc2
Wordpress Wordpress 1.0.2
Wordpress Wordpress 0.6.2
Wordpress Wordpress 0.711
Wordpress Wordpress 2.2.3
Wordpress Wordpress 1.0-platinum
Wordpress Wordpress 2.0.8
Wordpress Wordpress 2.2.1
Wordpress Wordpress 0.71-gold
Wordpress Wordpress 1.5.2
Wordpress Wordpress 2.0
Wordpress Wordpress 2.0.5
Wordpress Wordpress 2.0.6
Wordpress Wordpress 1.5
Wordpress Wordpress 1.5.1
Wordpress Wordpress 0.71
Wordpress Wordpress 1.6
1 EDB exploit available
5.4
CVE-2023-28664
The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'tax_name' parameter of the mdf_get_tax_options_in_widget action, which can only be triggered by an authenticated user....
Pluginus Wordpress Meta Data And Taxonomies Filter
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-21012
CVE-2023-21075
CVE-2021-3923
CVE-2023-25664
CVE-2023-21034
dos
CVE-2022-46169
unprivileged
reflected XSS
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »