| Date |
Description |
| 2010-08-05 | WordPress NextGEN Smooth Gallery Blind SQL Injection Vulnerability | | |
| 2010-07-23 | WordPress Plugin myLDlinker SQL Injection Vulnerability | | |
| 2010-07-10 | Wordpress Firestats Remote Configuration File Download | | |
| 2010-06-25 | Vulnerabilities in Cimy Counter for WordPress | | |
| 2010-06-08 | WordPress Gigya Socialize Plugin Cross-Site Scripting Vulnerabilities | | |
| 2010-04-06 | XSS Vulnerability in NextGEN Gallery Wordpress Plugin | | |
| 2010-03-02 | Wordpress 2.9.1 wp-admin Cross-Site Scripting Vulnerability | | |
| 2010-02-23 | WordPress Copperleaf Photolog SQL Injection Vulnerability | | |
| 2010-02-19 | Wordpress <= 2.9 Denial of Service | | |
| 2010-02-19 | Wordpress script <== x.x.x (Events Plugins) SQL Injection Vulnerability | | |
| 2010-02-19 | WordPress 2.9 plugin wp-wall (XSS) Cross Site Scripting Vulnerability | | |
| 2010-02-19 | Joomla JD-WordPress Remote File Include Exploit | | |
| 2010-02-19 | Wordpress Resource exhaustion Exploit | | |
| 2010-02-19 | WordPress Pyrmont V2. SQL Injection Vulnerability | | |
| 2010-02-15 | WordPress Copperleaf Photolog SQL injection | | |
| 2010-02-13 | WordPress >= 2.9 Failure to Restrict URL Access | | |
| 2010-01-02 | Wordpress Events Plugin SQL Injection Vulnerability | | |
| 2009-12-31 | 0day Wordpress DOS <= 2.9 | | |
| 2009-12-18 | WordPress and Pyrmont V2. SQL Injection Vulnerability | | |
| 2009-12-07 | Vulnerabilities in WP-Cumulus for WordPress | | |
| 2009-12-05 | Wordpress Image Manager Plugins Shell Upload Vulnerability | | |
| 2009-11-25 | Vulnerabilities in WP-Cumulus <= 1.20 for WordPress | | |
| 2009-11-13 | WordPress Arbitrary File Upload and Cross Site Scripting Vulnerabilities | | |
| 2009-11-13 | Wordpress Plugin WP-Syntax <= 0.9.1 Remote Command Execution PoC | | |
| 2009-11-11 | WordPress <= 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution | | |
| 2009-11-11 | Fedora Security Update Fixes WordPress-MU Denial of Service Issue | | |
| 2009-11-10 | WordPress 2.0 - 2.7.1 admin.php Module Configuration Security Bypass Vulnerability | | |
| 2009-11-10 | WordPress 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution | | |
| 2009-11-10 | WordPress MU 1.2.2 - 1.3.1 'wp-includes/wpmu-functions.php' Cross-Site Scripting Vulnerability | | |
| 2009-10-27 | Fedora Security Update Fixes WordPress Denial of Service Vulnerability | | |
| 2009-10-23 | DM Albums for WordPress "delete_album" Directory Traversal Issue | | |
| 2009-10-22 | WordPress < 2.8.1 Security Bypass 0day | | |
| 2009-10-21 | WordPress Trackback Remote Denial of Service Vulnerability | | |
| 2009-10-20 | JD-WordPress for Joomla "mosConfig_absolute_path" Inclusion Issue | | |
| 2009-10-19 | Joomla JD-WordPress 2.0 RC2 remote file icnlusion | | |
| 2009-09-02 | WordPress Privileges Unchecked in admin.php and Multiple Information Disclosures | | |
| 2009-08-28 | WP-Syntax for WordPress "test_filter[wp_head]" Code Injection Vulnerability | | |
| 2009-08-27 | Wordpress Plugin WP-Syntax <= 0.9.1 Remote Command Execution | | |
| 2009-08-24 | Debian Security Update Fixes Wordpress Security Bypass Vulnerabilities | | |
| 2009-08-17 | Fedora Security Update Fixes WordPress-MU Multiple Vulnerabilities | | |
| 2009-08-12 | Fedora Security Update Fixes WordPress Admin Pass Reset Vulnerability | | |
| 2009-08-11 | Wordpress <= 2.8.3 Remote Admin Reset Password Vulnerability | | |
| 2009-08-07 | Fedora Security Update Fixes WordPress Privilege Escalation Issues | | |
| 2009-07-30 | Fedora Security Update Fixes WordPress Cross Site Scripting Issue | | |
| 2009-07-27 | WordPress Plugin FireStats <= 1.6.1(fs_javascript) RFI Vulnerability | | |
| 2009-07-24 | Wordpress 2.8.1 (url) Remote Cross Site Scripting Exploit | | |
| 2009-07-20 | Fedora Security Update Fixes WordPress Security Bypass Vulnerabilities | | |
| 2009-07-15 | WordPress Plugin My Category Order <= 2.8 SQL Injection Vulnerability | | |
| 2009-07-10 | WordPress Privileges Unchecked in admin.php and Multiple Information | | |
| 2009-07-09 | WordPress Media Holder (mediaHolder.php id) SQL Injection vulnerability | | |
| 2009-07-09 | WordPress Multiple Security Bypass and Information Disclosure Issues | | |
| 2009-07-02 | Wordpress Plugin st_newsletter (stnl_iframe.php) SQL Injection Vulnerability | | |
| 2009-06-30 | WordPress Plugin DM Albums 1.9.2 Remote File Disclosure Vulnerability | | |
| 2009-06-30 | WordPress Plugin Related Sites 2.1 Blind SQL Injection Vulnerability | | |
| 2009-06-29 | WordPress Plugin DM Albums 1.9.2 Remote File Inclusion Vuln | | |
| 2009-06-15 | WordPress Plugin Photoracer 1.0 (id) SQL Injection Vulnerability | | |
| 2009-05-26 | Wordpress Plugin Lytebox (wp-lytebox) Local File Inclusion Vulnerability | | |
| 2009-04-15 | Fedora Security Update Fixes Wordpress-mu Cross Site Scripting Issue | | |
| 2009-03-18 | FMoblog Plugin for WordPress "id" Remote SQL Injection Vulnerability | | |
| 2009-03-17 | Wordpress Plugin fMoblog 2.1 (id) SQL Injection Vulnerability | | |
| 2009-03-10 | Wordpress MU < 2.7 'HOST' HTTP Header XSS Vulnerability | | |
| 2009-01-12 | Wordpress plugin WP-Forum 1.7.8 Remote SQL Injection Vulnerability | | |
| 2008-12-22 | Wordpress Plugin Page Flip Image Gallery <= 0.2.2 Remote FD Vuln | | |
| 2008-11-07 | Fedora Security Update Fixes Wordpress Snoopy Code Execution | | |
| 2008-10-29 | Wordpress Plugin e-Commerce <= 3.4 Arbitrary File Upload Exploit | | |
| 2008-10-26 | WordPress Media Holder (mediaHolder.php id) SQL Injection Vuln | | |
| 2008-10-17 | Wordpress Plugin st_newsletter (stnl_iframe.php) SQL Injection Vuln | | |
| 2008-09-15 | WordPress "user_login" Column SQL Truncation Vulnerability | | |
| 2008-09-10 | Wordpress 2.6.1 (SQL Column Truncation) Admin Takeover Exploit | | |
| 2008-09-10 | Fedora Security Update Fixes WordPress SSL Enforcement Weakness | | |
| 2008-09-07 | Wordpress 2.6.1 SQL Column Truncation Vulnerability | | |
| 2008-07-24 | Wordpress Plugin Download Manager 0.2 Arbitrary File Upload Exploit | | |
| 2008-07-07 | Debian Security Update Fixes WordPress Security Bypass Issues | | |
| 2008-05-05 | Fedora Security Update Fixes WordPress Privilege Escalation Issue | | |
| 2008-04-28 | WordPress Cookie Integrity Protection Privilege Escalation Vulnerability | | |
| 2008-04-24 | Spreadsheet for WordPress "ss_id" Remote SQL Injection Vulnerability | | |
| 2008-04-22 | Wordpress Plugin Spreadsheet <= 0.6 SQL Injection Vulnerability | | |
| 2008-03-31 | Wordpress Plugin Download (dl_id) SQL Injection Vulnerability | | |
| 2008-02-26 | Wordpress Plugin Sniplets 1.1.2 (RFI/XSS/RCE) Multiple Vulnerabilities | | |
| 2008-02-18 | Photo Album Plugin for WordPress Multiple SQL Injection Vulnerabilities | | |
| 2008-02-16 | Wordpress Photo album Remote SQL Injection Vulnerability | | |
| 2008-02-15 | Wordpress Plugin Simple Forum 1.10-1.11 SQL Injection Vulnerability | | |
| 2008-02-15 | Wordpress Plugin Simple Forum 2.0-2.1 SQL Injection Vulnerability | | |
| 2008-02-13 | Fedora Security Update Fixes WordPress XML-RPC Post Editing Issue | | |
| 2008-02-07 | WordPress XML-RPC Implementation Arbitrary Post Editing Vulnerability | | |
| 2008-02-05 | Wordpress MU < 1.3.2 active_plugins option Code Execution Exploit | | |
| 2008-02-03 | Wordpress Plugin st_newsletter Remote SQL Injection Vulnerability | | |
| 2008-02-02 | Wordpress Plugin dmsguestbook 1.7.0 Multiple Remote Vulnerabilities | | |
| 2008-02-02 | Wordpress Plugin Wordspew Remote SQL Injection Vulnerability | | |
| 2008-01-31 | FGallery Plugin for WordPress "album" SQL Query Injection Vulnerability | | |
| 2008-01-31 | AdServe Plugin for WordPress "id" Parameter SQL Injection Vulnerability | | |
| 2008-01-31 | WassUp Plugin for WordPress "to_date" SQL Injection Vulnerability | | |
| 2008-01-31 | WP-Cal Plugin for WordPress "id" SQL Query Injection Vulnerability | | |
| 2008-01-30 | Wordpress Plugin Adserve 0.2 adclick.php SQL Injection Exploit | | |
| 2008-01-30 | Wordpress Plugin WassUp 1.4.3 (spy.php to_date) SQL Injection Exploit | | |
| 2008-01-27 | Wordpress Plugin WP-Cal 0.3 editevent.php SQL Injection Vulnerability | | |
| 2008-01-27 | Wordpress plugin fGallery 2.4.1 fimrss.php SQL Injection Vulnerability | | |
| 2008-01-25 | Permalinks Migration Plugin for WordPress Cross Site Request Forgery | | |
| 2008-01-22 | WP-Forum Plugin for WordPress "user" SQL Query Injection Vulnerability | | |
| 2008-01-19 | Wordpress plugin WP-Forum 1.7.4 Remote SQL Injection Vulnerability | | |
| 2008-01-06 | Wordpress Plugin Wp-FileManager 1.2 Remote Upload Vulnerability | | |
| 2008-01-03 | Fedora Security Update Fixes WordPress Multiple Remote Vulnerabilities | | |
| 2007-12-11 | WordPress "s" Parameter Handling Remote SQL Injection Vulnerability | | |
| 2007-12-11 | Wordpress <= 2.3.1 Charset Remote SQL Injection Vulnerability | | |
| 2007-12-05 | Wordpress Plugin PictPress <= 0.91 Remote File Disclosure Vulnerability | | |
| 2007-11-21 | WordPress Cookies Processing Authentication Bypass Weakness | | |
| 2007-11-06 | BackUpWordPress "bkpwp_plugin_path" PHP File Inclusion Vulnerabilities | | |
| 2007-11-01 | WordPress Plugin BackUpWordPress <= 0.4.2b RFI Vulnerability | | |
| 2007-10-29 | WordPress "posts_columns" Parameter Cross Site Scripting Vulnerability | | |
| 2007-09-14 | Wordpress Multiple Versions Pwnpress Exploitation Tookit (0.2pub) | | |
| 2007-09-13 | Wordpress Multiple Parameter Cross Site Scripting and SQL Injection Issues | | |
| 2007-08-31 | Fedora Security Update Fixes WordPress Cross Site Scripting Vulnerability | | |
| 2007-08-01 | WordPress "style" Parameter Processing Cross Site Scripting Vulnerability | | |
| 2007-06-26 | WordPress 2.2 (wp-app.php) Arbitrary File Upload Exploit | | |
| 2007-06-26 | WordPress Security Update Fixes Code Execution and SQL Injection Vulnerabilities | | |
| 2007-06-11 | OpenPKG Security Update Fixes WordPress XML-RPC SQL Injection Vulnerability | | |
| 2007-06-07 | WordPress XML-RPC Interface "wp_suggestCategories()" SQL Injection Vulnerability | | |
| 2007-06-06 | Wordpress 2.2 (xmlrpc.php) Remote SQL Injection Exploit | | |
| 2007-05-21 | WordPress "cookie" Parameter Handling Remote SQL Query Injection Vulnerability | | |
| 2007-05-21 | Wordpress 2.1.3 admin-ajax.php SQL Injection Blind Fishing Exploit | | |
| 2007-05-02 | MyFlash Plugin for WordPress "wppath" Parameter Remote File Inclusion Vulnerability | | |
| 2007-05-02 | Debian Security Update Fixes WordPress Cross Site Scripting and Security Bypass Issues | | |
| 2007-05-02 | WP-Table Plugin for WordPress "wppath" Parameter Remote File Inclusion Vulnerability | | |
| 2007-05-02 | WordTube Plugin for WordPress "wppath" Parameter Remote File Inclusion Vulnerability | | |
| 2007-05-01 | Wordpress plugin wp-Table <= 1.43 (inc_dir) RFI Vulnerability | | |
| 2007-05-01 | Wordpress plugin wordTube <= 1.43 (wpPATH) RFI Vulnerability | | |
| 2007-05-01 | Wordpress plugin myflash <= 1.00 (wppath) RFI Vulnerability | | |
| 2007-04-30 | MyGallery Plugin for Wordpress "myPath" Parameter Remote File Inclusion Vulnerability | | |
| 2007-04-29 | Wordpress Plugin myGallery <= 1.4b4 Remote File Inclusion Vulnerability | | |
| 2007-04-04 | WordPress "XML-RPC" Module Remote SQL Injection and Security Bypass Vulnerabilities | | |
| 2007-04-03 | Wordpress 2.1.2 (xmlrpc) Remote SQL Injection Exploit | | |
| 2007-03-21 | Gentoo Security Update Fixes Multiple Wordpress Cross Site Scripting Vulnerabilities | | |
| 2007-03-19 | WordPress "PHP_SELF" Variable Handling Client-Side Cross Site Scripting Vulnerability | | |
| 2007-03-13 | WordPress "wp_title()" and "single_month_title()" Cross Site Scripting Vulnerability | | |
| 2007-03-05 | WordPress "comment_text_phpfilter()" and "get_theme_mcommand()" Vulnerabilities | | |
| 2007-02-27 | WordPress "wp-includes/functions.php" Client-Side Cross Site Scripting Vulnerability | | |
| 2007-02-26 | NoMoKeTo Module for phpBB "phpbb_root_path" Remote File Inclusion Vulnerability | | |
| 2007-02-26 | WordPress "wp_explain_nonce()" Function Client-Side Cross Site Scripting Vulnerability | | |
| 2007-01-17 | Gentoo Security Update Fixes WordPress SQL Injection and Cross Site Scripting Issues | | |
| 2007-01-10 | Wordpress <= 2.0.6 wp-trackback.php Remote SQL Injection Exploit | | |
| 2007-01-09 | OpenPKG Security Update Fixes WordPress Trackback Charset SQL Injection Issue | | |
| 2007-01-07 | Wordpress 2.0.5 Trackback UTF-7 Remote SQL Injection Exploit | | |
| 2007-01-06 | WordPress Trackback Charset SQL Injection and Admin Cross Site Scripting Vulnerabilities | | |
| 2007-01-06 | WordPress "wp-login.php" Authentication Process Information Disclosure Vulnerability | | |
| 2006-12-30 | Enigma 2 WordPress Bridge (boarddir) Remote File Include Vulnerability | | |
| 2006-12-27 | WordPress "get_file_description()" Function Client-Side Cross Site Scripting Vulnerability | | |
| 2006-11-21 | Gentoo Security Update Fixes WordPress Directory Traversal and Security Bypass | | |
| 2006-11-03 | OpenPKG Security Update Fixes WordPress Multiple Security Bypass Vulnerabilities | | |
| 2006-11-02 | WordPress Remote Directory Traversal and Security Bypass Vulnerabilities | | |
| 2006-08-16 | WP-DB Backup Plugin for WordPress "backup" Parameter Directory Traversal Vulnerability | | |
| 2006-07-31 | WordPress Unspecified Parameter Handling Multiple Vulnerabilities | | |
| 2006-07-17 | Rocks "mount-loop" and "umount-loop" Arguments Handling Privilege Escalation Vulnerability | | |
| 2006-07-04 | WordPress "paged" Parameter Table Prefix and Full Path Disclosure Vulnerabilities | | |
| 2006-06-12 | Gentoo Security Update Fixes WordPress Remote Command Injection Vulnerability | | |
| 2006-05-26 | WordPress User Profile Handling Remote PHP Command Injection Vulnerability | | |
| 2006-05-25 | WordPress <= 2.0.2 (cache) Remote Shell Injection Exploit | | |
| 2006-03-05 | Gentoo Security Update Fixes WordPress SQL Injection Vulnerability | | |
| 2006-03-01 | WordPress Cross Site Scripting And Full Path Disclosure Vulnerabilities | | |
| 2006-01-16 | WP-Stats WordPress Plug-in "author" Remote SQL Injection Vulnerability | | |
| 2005-11-25 | PhpWordPress Multiple Parameters Remote SQL Injection Vulnerability | | |
| 2005-08-10 | WordPress "cache_lastpostdate" Remote Code Execution Issue | | |
| 2005-08-10 | Wordpress <= 1.5.1.3 Remote Code Execution eXploit (metasploit) | | |
| 2005-08-09 | Wordpress <= 1.5.1.3 Remote Code Execution 0-Day Exploit | | |
| 2005-07-04 | Gentoo Security Update Fixes Multiple WordPress Vulnerabilities | | |
| 2005-06-30 | Wordpress <= 1.5.1.2 xmlrpc Interface SQL Injection Exploit | | |
| 2005-06-30 | WordPress SQL Injection and Cross Site Scripting Vulnerabilities | | |
| 2005-06-22 | WordPress <= 1.5.1.1 SQL Injection Exploit | | |
| 2005-06-21 | WordPress <= 1.5.1.1 "add new admin" SQL Injection Exploit | | |
| 2005-06-21 | WordPress <= 1.5.1.1 ""add new admin"" SQL Injection Exploit | | |
| 2005-05-30 | WordPress "cat_ID" Remote SQL Injection Vulnerability | | |
| 2004-10-10 | WordPress Blog HTTP Splitting Vulnerability | | |