Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
wordpress wordpress 4.7 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2017-1001000
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts...
Wordpress Wordpress 4.7.1
Wordpress Wordpress 4.7.2
Wordpress Wordpress 4.7
1 Nmap script available
3 Github repositories available
7.5
CVSSv3
CVE-2017-14722
Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename....
Wordpress Wordpress 4.7.5
Wordpress Wordpress 4.8
Wordpress Wordpress 4.7.3
Wordpress Wordpress 4.7.4
Wordpress Wordpress 4.7
Wordpress Wordpress 4.8.1
Wordpress Wordpress 4.7.1
Wordpress Wordpress 4.7.2
7.5
CVSSv3
CVE-2017-14719
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components....
Wordpress Wordpress 4.7.1
Wordpress Wordpress 4.7.2
Wordpress Wordpress 4.6.6
Wordpress Wordpress 4.6.5
Wordpress Wordpress 4.6.4
Wordpress Wordpress 4.5.7
Wordpress Wordpress 4.5.6
Wordpress Wordpress 4.5
Wordpress Wordpress 4.4.9
Wordpress Wordpress 4.4.11
Wordpress Wordpress 4.4.10
Wordpress Wordpress 4.3.5
Wordpress Wordpress 4.3.4
Wordpress Wordpress 4.3
Wordpress Wordpress 4.2.9
Wordpress Wordpress 4.2.16
Wordpress Wordpress 4.2.15
Wordpress Wordpress 4.2
Wordpress Wordpress 4.1.9
Wordpress Wordpress 4.1.2
Wordpress Wordpress 4.1.19
Wordpress Wordpress 4.1.11
Wordpress Wordpress 4.1.10
Wordpress Wordpress 4.0.5
Wordpress Wordpress 4.0.4
Wordpress Wordpress 4.0.15
Wordpress Wordpress 4.0.14
Wordpress Wordpress 3.9.8
Wordpress Wordpress 3.9.7
Wordpress Wordpress 3.9.19
Wordpress Wordpress 3.9.18
Wordpress Wordpress 3.9.11
Wordpress Wordpress 3.9.10
Wordpress Wordpress 3.9.1
Wordpress Wordpress 3.8.4
Wordpress Wordpress 3.8.3
Wordpress Wordpress 3.8.17
Wordpress Wordpress 3.8.16
Wordpress Wordpress 3.8.1
Wordpress Wordpress 3.8
Wordpress Wordpress 4.7
Wordpress Wordpress 4.8.1
Wordpress Wordpress 4.6.7
Wordpress Wordpress 4.5.9
Wordpress Wordpress 4.5.8
Wordpress Wordpress 4.5.10
Wordpress Wordpress 4.5.1
Wordpress Wordpress 4.4.4
Wordpress Wordpress 4.4.3
Wordpress Wordpress 4.4.2
Wordpress Wordpress 4.3.7
Wordpress Wordpress 4.3.6
Wordpress Wordpress 4.3.10
Wordpress Wordpress 4.3.1
Wordpress Wordpress 4.2.4
Wordpress Wordpress 4.2.3
Wordpress Wordpress 4.2.2
Wordpress Wordpress 4.2.10
Wordpress Wordpress 4.2.1
Wordpress Wordpress 4.1.4
Wordpress Wordpress 4.1.3
Wordpress Wordpress 4.1.13
Wordpress Wordpress 4.1.12
Wordpress Wordpress 4.0.7
Wordpress Wordpress 4.0.6
Wordpress Wordpress 4.0.17
Wordpress Wordpress 4.0.16
Wordpress Wordpress 4.0
Wordpress Wordpress 3.9.9
Wordpress Wordpress 3.9.20
Wordpress Wordpress 3.9.2
Wordpress Wordpress 3.9.13
Wordpress Wordpress 3.9.12
Wordpress Wordpress 3.8.6
Wordpress Wordpress 3.8.5
Wordpress Wordpress 3.8.19
Wordpress Wordpress 4.7.5
Wordpress Wordpress 4.8
Wordpress Wordpress 4.6.1
Wordpress Wordpress 4.6
Wordpress Wordpress 4.5.3
Wordpress Wordpress 4.5.2
Wordpress Wordpress 4.4.6
Wordpress Wordpress 4.4.5
Wordpress Wordpress 4.3.9
Wordpress Wordpress 4.3.8
Wordpress Wordpress 4.3.12
Wordpress Wordpress 4.3.11
Wordpress Wordpress 4.2.6
Wordpress Wordpress 4.2.5
Wordpress Wordpress 4.2.12
Wordpress Wordpress 4.2.11
Wordpress Wordpress 4.1.6
Wordpress Wordpress 4.1.5
Wordpress Wordpress 4.1.16
Wordpress Wordpress 4.1.15
Wordpress Wordpress 4.1.14
Wordpress Wordpress 4.0.9
Wordpress Wordpress 4.0.8
Wordpress Wordpress 4.0.19
Wordpress Wordpress 4.0.18
Wordpress Wordpress 4.0.10
Wordpress Wordpress 4.0.1
Wordpress Wordpress 3.9.4
Wordpress Wordpress 3.9.3
Wordpress Wordpress 3.9.15
Wordpress Wordpress 3.9.14
Wordpress Wordpress 3.8.8
Wordpress Wordpress 3.8.7
Wordpress Wordpress 3.8.20
Wordpress Wordpress 3.8.2
Wordpress Wordpress 3.8.13
Wordpress Wordpress 3.8.12
Wordpress Wordpress 3.7.6
Wordpress Wordpress 3.7.5
Wordpress Wordpress 3.7.19
Wordpress Wordpress 3.7.18
Wordpress Wordpress 3.7.11
Wordpress Wordpress 3.7.10
Wordpress Wordpress 3.4.2
Wordpress Wordpress 3.4.1
Wordpress Wordpress 3.2
Wordpress Wordpress 3.1.4
Wordpress Wordpress 3.0.4
Wordpress Wordpress 3.0.3
Wordpress Wordpress 3.8.18
Wordpress Wordpress 3.8.11
Wordpress Wordpress 3.8.10
Wordpress Wordpress 3.7.4
Wordpress Wordpress 3.7.3
Wordpress Wordpress 3.7.17
Wordpress Wordpress 3.7.16
Wordpress Wordpress 3.7.1
Wordpress Wordpress 3.7
Wordpress Wordpress 3.6.1
Wordpress Wordpress 3.4
Wordpress Wordpress 3.3.3
Wordpress Wordpress 3.1.3
Wordpress Wordpress 3.1.2
Wordpress Wordpress 3.0.1
Wordpress Wordpress 3.0
Wordpress Wordpress 3.0.2
Wordpress Wordpress 3.7.9
Wordpress Wordpress 3.7.22
Wordpress Wordpress 3.7.21
Wordpress Wordpress 3.7.15
Wordpress Wordpress 3.7.14
Wordpress Wordpress 3.6
Wordpress Wordpress 3.5.2
Wordpress Wordpress 3.3.2
Wordpress Wordpress 3.3.1
Wordpress Wordpress 3.1.1
Wordpress Wordpress 3.1
Wordpress Wordpress 4.7.3
Wordpress Wordpress 4.7.4
Wordpress Wordpress 4.6.3
Wordpress Wordpress 4.6.2
Wordpress Wordpress 4.5.5
Wordpress Wordpress 4.5.4
Wordpress Wordpress 4.4.8
Wordpress Wordpress 4.4.7
Wordpress Wordpress 4.4.1
Wordpress Wordpress 4.4
Wordpress Wordpress 4.3.3
Wordpress Wordpress 4.3.2
Wordpress Wordpress 4.2.8
Wordpress Wordpress 4.2.7
Wordpress Wordpress 4.2.14
Wordpress Wordpress 4.2.13
Wordpress Wordpress 4.1.8
Wordpress Wordpress 4.1.7
Wordpress Wordpress 4.1.18
Wordpress Wordpress 4.1.17
Wordpress Wordpress 4.1.1
Wordpress Wordpress 4.1
Wordpress Wordpress 4.0.3
Wordpress Wordpress 4.0.2
Wordpress Wordpress 4.0.13
Wordpress Wordpress 4.0.12
Wordpress Wordpress 4.0.11
Wordpress Wordpress 3.9.6
Wordpress Wordpress 3.9.5
Wordpress Wordpress 3.9.17
Wordpress Wordpress 3.9.16
Wordpress Wordpress 3.9
Wordpress Wordpress 3.8.9
Wordpress Wordpress 3.8.22
Wordpress Wordpress 3.8.21
Wordpress Wordpress 3.8.15
Wordpress Wordpress 3.8.14
Wordpress Wordpress 3.7.8
Wordpress Wordpress 3.7.7
Wordpress Wordpress 3.7.20
Wordpress Wordpress 3.7.2
Wordpress Wordpress 3.7.13
Wordpress Wordpress 3.7.12
Wordpress Wordpress 3.5.1
Wordpress Wordpress 3.5
Wordpress Wordpress 3.3
Wordpress Wordpress 3.2.1
Wordpress Wordpress 3.0.6
Wordpress Wordpress 3.0.5
3 Github repositories available
5.3
CVSSv3
CVE-2017-5487
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request....
Wordpress Wordpress
1 EDB exploit available
16 Github repositories available
NA
CVE-2013-2703
Cross-site request forgery (CSRF) vulnerability in the Facebook Members plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify this plugin's settings....
Crunchify Facebook Members 5.0
Crunchify Facebook Members 4.7
Crunchify Facebook Members 4.6.1
Crunchify Facebook Members 4.6
Crunchify Facebook Members 4.5.3
Crunchify Facebook Members
Crunchify Facebook Members 5.0.2
Crunchify Facebook Members 5.0.3
Crunchify Facebook Members 5.0.1
9.8
CVSSv3
CVE-2017-18571
The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316....
Search Everything Project Search Everything
6.1
CVSSv3
CVE-2017-5490
Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to...
Wordpress Wordpress
3 Github repositories available
NA
CVE-2014-4552
Cross-site scripting (XSS) vulnerability in library/includes/payment/paypalexpress/DoDirectPayment.php in the Spotlight (spotlightyour) plugin 4.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the paymentType parameter....
Spotlightyour Spotlightyour
8.8
CVSSv3
CVE-2017-5489
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload....
Wordpress Wordpress
5.3
CVSSv3
CVE-2017-5491
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name....
Wordpress Wordpress
3 Github repositories available
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
HTML injection
CVE-2023-21014
CVE-2023-21052
arbitrary
CVE-2023-27579
open redirect
CVE-2023-21019
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »