Security: WordPress/wordpress-develop
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
WordPress: Authenticated disclosure of password-protected posts and pagesGHSA-pmmh-2f36-wvhq published
Apr 15, 2021 by ehtiModerate -
WordPress: Authenticated XXE attack when installation is running PHP 8GHSA-rv47-pc52-qrhh published
Apr 15, 2021 by ehtiModerate -
WordPress: 'set-screen-option' filter misuse by plugins leading to privilege escalationGHSA-4vpv-fgg2-gcqc published
Jun 12, 2020 by ehtiModerate -
WordPress: Authenticated self-XSS via theme uploadsGHSA-87h4-phjv-rm6p published
Jun 12, 2020 by ehtiLow -
WordPress: Open redirect in wp_validate_redirect()GHSA-q6pw-gvf4-5fj5 published
Jun 12, 2020 by ehtiLow -
WordPress: Authenticated XSS via media attachment pageGHSA-8q2w-5m27-wm27 published
Jun 12, 2020 by ehtiModerate -
WordPress: Authenticated XSS through embed blockGHSA-rpwf-hrh2-39jf published
Jun 12, 2020 by ehtiModerate -
Cross-site scripting (XSS) in Search block - WordPressGHSA-vccm-6gmc-qhjh published
Apr 30, 2020 by ehtiLow -
WordPress: Cross-site scripting in stats method (object cache)GHSA-568w-8m88-8g2c published
Apr 30, 2020 by ehtiModerate -
WordPress: Unauthenticated disclosure of certain private postsGHSA-xhx9-759f-6p2w published
Apr 30, 2020 by ehtiLow