From 4f0a5bcf157a6fbce2d83c4a7aa8cd5f6a783395 Mon Sep 17 00:00:00 2001 From: erwanlr Date: Wed, 26 Feb 2014 12:30:21 +0100 Subject: [PATCH] Fix #411 - Old WP Core CVEs added --- data/wp_vulns.xml | 2288 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 2288 insertions(+) diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index 3b218068..9c972e39 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -474,6 +474,30 @@ UNKNOWN + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -512,6 +536,30 @@ UNKNOWN + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -543,6 +591,30 @@ UNKNOWN + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -567,6 +639,30 @@ UNKNOWN + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -591,6 +687,30 @@ UNKNOWN + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -615,6 +735,30 @@ UNKNOWN + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -649,6 +793,30 @@ UNKNOWN + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -681,6 +849,30 @@ UNKNOWN + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -712,6 +904,30 @@ UNKNOWN + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -736,6 +952,30 @@ UNKNOWN + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -760,6 +1000,30 @@ UNKNOWN + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -784,6 +1048,38 @@ UNKNOWN + + wp-admin/press-this.php - Privilege Escalation + + 2011-5270 + + UNKNOWN + 3.0.6 + + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -808,6 +1104,38 @@ UNKNOWN + + wp-admin/press-this.php - Privilege Escalation + + 2011-5270 + + UNKNOWN + 3.0.6 + + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -846,6 +1174,38 @@ UNKNOWN + + wp-admin/press-this.php - Privilege Escalation + + 2011-5270 + + UNKNOWN + 3.0.6 + + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -877,6 +1237,38 @@ UNKNOWN + + wp-admin/press-this.php - Privilege Escalation + + 2011-5270 + + UNKNOWN + 3.0.6 + + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + @@ -908,6 +1300,70 @@ UNKNOWN + + wp-admin/press-this.php - Privilege Escalation + + 2011-5270 + + UNKNOWN + 3.0.6 + + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + @@ -932,6 +1388,78 @@ UNKNOWN + + wp-admin/press-this.php - Privilege Escalation + + 2011-5270 + + UNKNOWN + 3.0.6 + + + Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php + + 2012-6633 + + XSS + 3.3.3 + + + wp-admin/media-upload.php sensitive information disclosure or bypass + + 2012-6634 + + MULTI + 3.3.3 + + + wp-admin/includes/class-wp-posts-list-table.php sensitive information disclosure by visiting a draft + + 2012-6635 + + UNKNOWN + 3.3.3 + + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -956,6 +1484,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -980,6 +1548,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1018,6 +1626,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1042,6 +1690,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1073,6 +1761,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1097,6 +1825,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1128,6 +1896,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1152,6 +1960,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1183,6 +2031,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1207,6 +2095,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1238,6 +2166,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1269,6 +2237,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1300,6 +2308,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1324,6 +2372,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1348,6 +2436,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1379,6 +2507,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1417,6 +2585,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1441,6 +2649,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1472,6 +2720,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1504,6 +2792,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1528,6 +2856,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1552,6 +2920,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1583,6 +2991,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1600,6 +3048,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1624,6 +3112,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1648,6 +3176,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1672,6 +3240,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1710,6 +3318,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1741,6 +3389,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1780,6 +3468,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1815,6 +3543,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1832,6 +3600,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1856,6 +3664,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1880,6 +3728,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1897,6 +3785,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1914,6 +3842,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1938,6 +3906,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -1969,6 +3977,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -2000,6 +4048,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -2031,6 +4119,46 @@ SQLI + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -2062,6 +4190,46 @@ SQLI + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -2100,6 +4268,46 @@ SQLI + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -2132,6 +4340,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 + @@ -2164,6 +4412,46 @@ UNKNOWN + + wp-includes/comment.php bypass intended spam restrictions via a crafted URL + + 2010-5293 + + UNKNOWN + 3.0.2 + + + Multiple cross-site scripting (XSS) in the request_filesystem_credentials function in wp-admin/includes/file.php + + 2010-5294 + + XSS + 3.0.2 + + + Cross-site scripting (XSS) in wp-admin/plugins.php + + 2010-5295 + + XSS + 3.0.2 + + + wp-includes/capabilities.php when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. + + 2010-5296 + + AUTHBYPASS + 3.0.2 + + + When a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change. + + 2010-5297 + + AUTHBYPASS + 3.0 +