Wordpress 3.3.1 Multiple CSRF Vulnerabilities http://www.exploit-db.com/exploits/18791/ Wordpress 3.3.1 Multiple CSRF Vulnerabilities http://www.exploit-db.com/exploits/18791/ WordPress 3.3.2 Cross Site Scripting http://packetstormsecurity.org/files/113254 Multiple vulnerabilities including XSS and Privilege Escalation http://wordpress.org/news/2012/04/wordpress-3-3-2/ Wordpress 3.3.1 Multiple CSRF Vulnerabilities http://www.exploit-db.com/exploits/18791/ Reflected Cross-Site Scripting in WordPress 3.3 http://oldmanlab.blogspot.com/2012/01/wordpress-33-xss-vulnerability.html Multiple SQL Injection Vulnerabilities http://www.exploit-db.com/exploits/17465/ Wordpress <= 3.1.2 Clickjacking Vulnerability http://seclists.org/fulldisclosure/2011/Sep/219 SQL injection vulnerability in do_trackbacks() Wordpress function http://www.exploit-db.com/exploits/15684/ Wordpress 3.0.3 stored XSS IE7,6 NS8.1 http://www.exploit-db.com/exploits/15858/ WordPress 2.9 Failure to Restrict URL Access http://www.exploit-db.com/exploits/11441/ Wordpress DOS <= 2.9 http://www.exploit-db.com/exploits/11441/ WordPress <= 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution http://www.exploit-db.com/exploits/10089/ Wordpress <= 2.8.3 Remote Admin Reset Password Vulnerability http://www.exploit-db.com/exploits/9410/ Wordpress 2.8.1 (url) Remote Cross Site Scripting Exploit http://www.exploit-db.com/exploits/9250/ WordPress 2.0 - 2.7.1 admin.php Module Configuration Security Bypass Vulnerability http://www.exploit-db.com/exploits/10088/ Wordpress 2.6.1 (SQL Column Truncation) Admin Takeover Exploit http://www.exploit-db.com/exploits/6421/ Wordpress <= 2.3.1 Charset Remote SQL Injection Vulnerability http://www.exploit-db.com/exploits/4721/ WordPress 2.2 (wp-app.php) Arbitrary File Upload Exploit http://www.exploit-db.com/exploits/4113/ Wordpress 2.2 (xmlrpc.php) Remote SQL Injection Exploit http://www.exploit-db.com/exploits/4039/ Wordpress 2.1.3 admin-ajax.php SQL Injection Blind Fishing Exploit http://www.exploit-db.com/exploits/3960/ Wordpress 2.1.2 (xmlrpc) Remote SQL Injection Exploit http://www.exploit-db.com/exploits/3656/ Wordpress <= 2.0.6 wp-trackback.php Remote SQL Injection Exploit http://www.exploit-db.com/exploits/3109/ Wordpress 2.0.5 Trackback UTF-7 Remote SQL Injection Exploit http://www.exploit-db.com/exploits/3095/ WordPress <= 2.0.2 (cache) Remote Shell Injection Exploit http://www.exploit-db.com/exploits/6/ Wordpress <= 1.5.1.3 Remote Code Execution eXploit (metasploit) http://www.exploit-db.com/exploits/1145/ Wordpress <= 1.5.1.2 xmlrpc Interface SQL Injection Exploit http://www.exploit-db.com/exploits/1077/ WordPress <= 1.5.1.1 "add new admin" SQL Injection Exploit http://www.exploit-db.com/exploits/1059/ WordPress <= 1.5.1.1 SQL Injection Exploit http://www.exploit-db.com/exploits/1033/