Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wordpress-develop — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in wordpress-develop, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities associated with the wordpress-develop software product, focusing on security weakness classifications. It compiles data on common security issues such as cross-site scripting, SQL injection, and path traversal, covering reported incidents and patches from early 2020 through late 2023. Here, you can discover comprehensive details about how the WordPress development ecosystem handles security flaws, including tracking vendor advisories from the official WordPress project, understanding the root causes of specific weakness classes like OWASP Top Ten categories, and examining the historical vulnerability landscape for this specific product line. The page serves as a neutral resource for security researchers, developers, and system administrators seeking to assess the security posture of WordPress development branches. It does not promote any specific tools or services but rather provides factual, curated information on reported defects and their mitigations. Users can explore the timeline of patched vulnerabilities to identify recurring patterns in the codebase or review the impact of specific security fixes on the overall stability of the development version. This resource aims to enhance transparency regarding security practices in open-source web development by centralizing disparate reports into a single, searchable interface. By analyzing this aggregated data, stakeholders can better understand the frequency and severity of security issues affecting WordPress development environments, facilitating more informed decisions regarding software updates and risk management strategies.

Vendor: WordPress

CVE IDTitleCVSSSeverityPublished
CVE-2024-31211 Remote Code Execution in `WP_HTML_Token` CWE-502 5.5 Medium2024-04-04
CVE-2024-31210 PHP file upload bypass via Plugin installer CWE-434 7.7 High2024-04-04
CVE-2022-21662 Stored XSS in WordPress CWE-79 8.0 High2022-01-06
CVE-2022-21663 Authenticated Object Injection in Multisites in WordPress CWE-74 6.6 Medium2022-01-06
CVE-2022-21664 SQL injection in WordPress CWE-89 7.4 High2022-01-06
CVE-2022-21661 SQL injection in WordPress CWE-89 8.0 High2022-01-06
CVE-2021-39203 Private data disclosure/privilege escalation through the block editor in Wordpress CWE-200 6.8 Medium2021-09-09
CVE-2021-39202 WordPress 5.8 beta: Stored Cross-Site Scripting (XSS) vulnerability in widget CWE-79 7.6 High2021-09-09
CVE-2021-39201 Authenticated cross-site scripting (XSS) in WordPress editor CWE-79 7.6 High2021-09-09
CVE-2021-39200 Information Disclosure in wp_die() via JSONP in wordpress CWE-200 5.3 Medium2021-09-09
CVE-2021-29450 WordPress Authenticated disclosure of password-protected posts and pages CWE-200 6.5 Medium2021-04-15
CVE-2021-29447 WordPress Authenticated XXE attack when installation is running PHP 8 CWE-611 7.1 High2021-04-15
CVE-2020-4047 Authenticated XSS via media attachment page in WordPress CWE-80 6.8 Medium2020-06-12
CVE-2020-4048 Open redirect in wp_validate_redirect() in WordPress CWE-601 5.7 Medium2020-06-12
CVE-2020-4049 Authenticated self-XSS via theme uploads in WordPress CWE-80 2.4 Low2020-06-12
CVE-2020-4050 set-screen-option filter misuse by plugins leading to privilege escalation in WordPress CWE-288 3.5 Low2020-06-12
CVE-2020-4046 Authenticated XSS through embed block in WordPress CWE-80 5.4 Medium2020-06-12

All 17 known CVE vulnerabilities affecting wordpress-develop with full Chinese analysis, references, and POCs where available.