
CVE-2017-14720 – WordPress Core < 4.8.2 - Cross-Site Scripting via Template Name
https://notcve.org/view.php?id=CVE-2017-14720
19 Sep 2017 — Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name. Antes de la versión 4.8.2, WordPress permitía un ataque de Cross-Site Scripting (XSS) en la vista de plantilla de lista mediante un nombre de plantilla modificado. • http://www.securityfocus.com/bid/100912 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-14721 – WordPress Core < 4.8.2 - Stored Cross-Site Scripting via Plugin Names
https://notcve.org/view.php?id=CVE-2017-14721
19 Sep 2017 — Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name. Antes de la versión 4.8.2, WordPress permitía un ataque de Cross-Site Scripting (XSS) en el editor de plugins mediante un nombre de plugin modificado. • http://www.securityfocus.com/bid/100912 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-14722 – WordPress Core < 4.8.2 - Directory Traversal via Customizer
https://notcve.org/view.php?id=CVE-2017-14722
19 Sep 2017 — Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename. Antes de la versión 4.8.2, WordPress permitía un ataque de salto de directorio en el componente Customizer mediante un nombre de tema manipulado. • http://www.securityfocus.com/bid/100912 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2017-14724 – WordPress Core < 4.8.2 - Cross-Site Scripting in oEmbed
https://notcve.org/view.php?id=CVE-2017-14724
19 Sep 2017 — Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery. Antes de la versión 4.8.2, WordPress era vulnerable a Cross-Site Scripting (XSS) en oEmbed Discovery. • http://www.securityfocus.com/bid/100912 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-14725 – WordPress Core < 4.8.2 - Open Redirect in Admin Dashboard
https://notcve.org/view.php?id=CVE-2017-14725
19 Sep 2017 — Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php. Antes de la versión 4.8.2, WordPress era susceptible a un ataque de redirección abierta en wp-admin/edit-tag-form.php y wp-admin/user-edit.php. • http://www.securityfocus.com/bid/100912 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2017-14726 – WordPress Core < 4.8.2 - Cross-Site Scripting via Shortcodes
https://notcve.org/view.php?id=CVE-2017-14726
19 Sep 2017 — Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor. Antes de la versión 4.8.2, WordPress era vulnerable a un ataque de Cross-Site Scripting (XSS) mediante shortcodes en el editor visual TinyMCE. • http://www.securityfocus.com/bid/100912 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-14723 – WordPress Core < 4.8.2 - SQL Injection via Mishandled Placeholders
https://notcve.org/view.php?id=CVE-2017-14723
19 Sep 2017 — Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks. Antes de la versión 4.8.2, WordPress no gestionaba correctamente caracteres % y valores de sustitución adicionales en $wpdb->prepare, por lo que no abordaba correctamente la posibilidad de que los plugins o los temas permitiesen los ataques de inyección SQL. • http://www.securityfocus.com/bid/100912 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2017-9061 – WordPress Core < 4.7.5 - Stored Cross-Site Scripting via filenames
https://notcve.org/view.php?id=CVE-2017-9061
16 May 2017 — In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename. En WordPress anteriores a 4.7.5, existe una vulnerabilidad XSS (cross-site scripting) al intentar cargar archivos muy grandes, porque el mensaje de error no restringe adecuadamente la presentación del nombre de archivo. Several vulnerabilities were discovered in wordpress, a web blogging tool. They would al... • http://www.debian.org/security/2017/dsa-3870 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-9062 – WordPress Core < 4.7.5 - Mishandling Post Meta Values via XML-RPC
https://notcve.org/view.php?id=CVE-2017-9062
16 May 2017 — In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API. En WordPress anteriores a 4.7.5, existe una manipulación incorrecta de los valores meta-datos al hacer el post en la API XML-RPC. Several vulnerabilities were discovered in wordpress, a web blogging tool. They would allow remote attackers to force password resets, and perform various cross-site scripting and cross-site request forgery attacks. • http://www.debian.org/security/2017/dsa-3870 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-285: Improper Authorization CWE-352: Cross-Site Request Forgery (CSRF) CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2017-9063 – WordPress Core < 4.7.5 - Cross-Site Scripting via Customizer
https://notcve.org/view.php?id=CVE-2017-9063
16 May 2017 — In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session. En WordPress anteriores a 4.7.5, existe una vulnerabilidad de XSS (cross-site scripting) relacionada con la salida del personalizador, en una sesión de personalización no válida. Several vulnerabilities were discovered in wordpress, a web blogging tool. They would allow remote attackers to force password resets, and perform various cross-site scripting and cross... • http://www.debian.org/security/2017/dsa-3870 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •