|
|
Log in / Subscribe / Register

wordpress: multiple vulnerabilities

Package(s):wordpress CVE #(s):CVE-2015-2213 CVE-2015-5730 CVE-2015-5731 CVE-2015-5732 CVE-2015-5733 CVE-2015-5734
Created:August 7, 2015 Updated:August 12, 2015
Description: From the Arch Linux advisory:

- CVE-2015-2213: SQL injection in comments ID.

- CVE-2015-5730: Timing attack in widgets.

- CVE-2015-5731: Denial of service by locking a post from being edited.

- CVE-2015-5732, CVE-2015-5733 CVE-2015-5734: XSS.

A remote attacker could lock a post from being edited, or compromise a site running wordpress.

Alerts:
Debian DSA-3383-1 wordpress 2015-10-29
Debian-LTS DLA-294-1 wordpress 2015-08-19
Fedora FEDORA-2015-12235 wordpress 2015-08-13
Fedora FEDORA-2015-12148 wordpress 2015-08-13
Debian DSA-3332-1 wordpress 2015-08-11
Mageia MGASA-2015-0309 wordpress 2015-08-10
Arch Linux ASA-201508-2 wordpress 2015-08-07

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds