Security: WordPress/wordpress-develop
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Remote Code Execution in `WP_HTML_Token`GHSA-m257-q4m5-j653 published
Apr 3, 2024 by peterwilsonccModerate -
PHP file upload bypass via Plugin installerGHSA-x79f-xrjv-jx5r published
Apr 3, 2024 by peterwilsonccHigh -
WordPress: SQL injection due to improper sanitization in WP_Meta_QueryGHSA-jp3p-gw8h-6x86 published
Jan 6, 2022 by ehtiModerate -
WordPress: Authenticated Object Injection in MultisitesGHSA-jmmq-m8p8-332h published
Jan 6, 2022 by ehtiLow -
WordPress: Stored XSS through authenticated usersGHSA-699q-3hj9-889w published
Jan 6, 2022 by ehtiModerate -
WordPress: SQL Injection through WP_QueryGHSA-6676-cqfm-gw84 published
Jan 6, 2022 by ehtiHigh -
WordPress 5.8 beta: Private data disclosure/privilege escalation through the block editorGHSA-qxvw-qxm9-qvg6 published
Sep 9, 2021 by ehtiModerate -
Authenticated cross-site scripting (XSS) in WordPress editorGHSA-wh69-25hr-h94v published
Sep 9, 2021 by ehtiModerate -
WordPress: Information Disclosure in wp_die() via JSONP, leading to CSRFGHSA-m9hc-7v5q-x8q5 published
Sep 9, 2021 by ehtiModerate -
WordPress 5.8 beta: Stored Cross-Site Scripting (XSS) vulnerability in widget editorGHSA-fr6h-3855-j297 published
Sep 9, 2021 by ehtiLow