diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index fc0702a1..1e10cbb3 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -94,7 +94,7 @@ 3.5.2 - WordPress 3.4 - 3.5.1 DoS in class-phpass.php + WordPress 3.4-3.5.1 DoS in class-phpass.php http://seclists.org/fulldisclosure/2013/Jun/65 53676 @@ -112,6 +112,7 @@ 94790 XSS + 3.5.2 WordPress TinyMCE Plugin Flash Applet Unspecified Spoofing Weakness @@ -119,6 +120,7 @@ 94787 UNKNOWN + 3.5.2 WordPress File Upload Unspecified Path Disclosure @@ -126,27 +128,31 @@ 94788 UNKNOWN + 3.5.2 - WordPress oEmbed Unspecified XML External Entity (XXE) Arbitrary File Disclosure + WordPress 3.5-3.5.1 oEmbed Unspecified XML External Entity (XXE) Arbitrary File Disclosure 94789 XXE + 3.5.2 - WordPress Multiple Role Remote Privilege Escalation + WordPress 3.5-3.5.1 Multiple Role Remote Privilege Escalation 94783 UNKNOWN + 3.5.2 - WordPress HTTP API Unspecified Server Side Request Forgery (SSRF) + WordPress 3.5-3.5.1 HTTP API Unspecified Server Side Request Forgery (SSRF) 94784 SSRF + 3.5.2