Wordpress Vulnerabilities
The following list includes some of the most critical Wordpress vulnerabilities known to the security community. In any case you find that there is anything missing in this list, please let us know and we will update it as soon as possible.
- WordPress Unrestricted File Upload Arbitrary PHP Code Execution
- WordPress Unchecked Privileges in admin.php and Multiple Information Disclosures
- WordPress MU wpmu-Blogs.php Crose Site Scrpting Vulnerability
- Wordpress user_login Column SQL Truncation Vulnerability
- Wordpress Column Truncation Allows Adminstrative Takeover (register)
- WordPress SQL Column Truncation Vulnerability (PoC)
- Wordpress Cookie Integrity Protection Vulnerability
- WordPress metaWeblog.editPost Post Arbitrary Modification (xmlrpc, Exploit, Patch)
- WordPress Charset SQL Injection Vulnerability
- WordPress wp_title() XSS
- WordPress Multiple Script Injection Vulnerabilities
- Multiple Vulnerabilities in WordPress (pingback, local files)
- WordPress Trackback UTF-7 SQL Injection (Exploit)
- WordPress CSRF Protection XSS Vulnerability
- WordPress Trackback Charset Decoding SQL Injection Vulnerability
- WordPress Persistent XSS (templates.php)
- Wordpress WP-DB Backup Plugin Directory Traversal
- WordPress DoS (Exploit)
- WordPress User Privilege Escalation
- WordPress Command Execution Vulnerability (Cache_lastpostdate)
- WordPress Multiple Vulnerability (wp-trackback.php)
- Multiple XSS Vulnerabilities in WordPress
- HTTP Response Splitting in WordPress