Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <pre><font color="#4E9A06">[+]</font> URL: http://kamillotv.wex.pl/
- <font color="#4E9A06">[+]</font> Started: Sat Dec 16 23:56:06 2017
- <font color="#4E9A06">[+]</font> robots.txt available under: 'http://kamillotv.wex.pl/robots.txt'
- <font color="#C4A000">[!]</font> The WordPress 'http://kamillotv.wex.pl/readme.html' file exists exposing a version number
- <font color="#4E9A06">[+]</font> Interesting header: SERVER: nginx
- <font color="#4E9A06">[+]</font> Interesting header: X-CACHE-STATUS: HIT
- <font color="#4E9A06">[+]</font> XML-RPC Interface available under: http://kamillotv.wex.pl/xmlrpc.php
- <font color="#4E9A06">[+]</font> WordPress version 4.3.1 (Released on 2015-09-15) identified from advanced fingerprinting, meta generator, rss generator, rdf generator, atom generator, readme, links opml
- <font color="#CC0000">[!]</font> 44 vulnerabilities identified from the version number
- <font color="#CC0000">[!]</font> Title: WordPress 3.7-4.4 - Authenticated Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8358
- Reference: https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/7ab65139c6838910426567849c7abed723932b87
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1564
- <font color="#3465A4">[i]</font> Fixed in: 4.3.2
- <font color="#CC0000">[!]</font> Title: WordPress 3.7-4.4 - Authenticated Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8358
- Reference: https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/7ab65139c6838910426567849c7abed723932b87
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1564
- <font color="#3465A4">[i]</font> Fixed in: 4.3.2
- <font color="#CC0000">[!]</font> Title: WordPress 3.7-4.4.1 - Local URIs Server Side Request Forgery (SSRF)
- Reference: https://wpvulndb.com/vulnerabilities/8376
- Reference: https://wordpress.org/news/2016/02/wordpress-4-4-2-security-and-maintenance-release/
- Reference: https://core.trac.wordpress.org/changeset/36435
- Reference: https://hackerone.com/reports/110801
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2222
- <font color="#3465A4">[i]</font> Fixed in: 4.3.3
- <font color="#CC0000">[!]</font> Title: WordPress 3.7-4.4.1 - Open Redirect
- Reference: https://wpvulndb.com/vulnerabilities/8377
- Reference: https://wordpress.org/news/2016/02/wordpress-4-4-2-security-and-maintenance-release/
- Reference: https://core.trac.wordpress.org/changeset/36444
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2221
- <font color="#3465A4">[i]</font> Fixed in: 4.3.3
- <font color="#CC0000">[!]</font> Title: WordPress <= 4.4.2 - SSRF Bypass using Octal & Hexedecimal IP addresses
- Reference: https://wpvulndb.com/vulnerabilities/8473
- Reference: https://codex.wordpress.org/Version_4.5
- Reference: https://github.com/WordPress/WordPress/commit/af9f0520875eda686fd13a427fd3914d7aded049
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4029
- <font color="#3465A4">[i]</font> Fixed in: 4.5
- <font color="#CC0000">[!]</font> Title: WordPress <= 4.4.2 - Reflected XSS in Network Settings
- Reference: https://wpvulndb.com/vulnerabilities/8474
- Reference: https://codex.wordpress.org/Version_4.5
- Reference: https://github.com/WordPress/WordPress/commit/cb2b3ed3c7d68f6505bfb5c90257e6aaa3e5fcb9
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6634
- <font color="#3465A4">[i]</font> Fixed in: 4.5
- <font color="#CC0000">[!]</font> Title: WordPress <= 4.4.2 - Script Compression Option CSRF
- Reference: https://wpvulndb.com/vulnerabilities/8475
- Reference: https://codex.wordpress.org/Version_4.5
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6635
- <font color="#3465A4">[i]</font> Fixed in: 4.5
- <font color="#CC0000">[!]</font> Title: WordPress 4.2-4.5.1 - MediaElement.js Reflected Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8488
- Reference: https://wordpress.org/news/2016/05/wordpress-4-5-2/
- Reference: https://github.com/WordPress/WordPress/commit/a493dc0ab5819c8b831173185f1334b7c3e02e36
- Reference: https://gist.github.com/cure53/df34ea68c26441f3ae98f821ba1feb9c
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4567
- <font color="#3465A4">[i]</font> Fixed in: 4.5.2
- <font color="#CC0000">[!]</font> Title: WordPress <= 4.5.1 - Pupload Same Origin Method Execution (SOME)
- Reference: https://wpvulndb.com/vulnerabilities/8489
- Reference: https://wordpress.org/news/2016/05/wordpress-4-5-2/
- Reference: https://github.com/WordPress/WordPress/commit/c33e975f46a18f5ad611cf7e7c24398948cecef8
- Reference: https://gist.github.com/cure53/09a81530a44f6b8173f545accc9ed07e
- Reference: http://avlidienbrunn.com/wp_some_loader.php
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4566
- <font color="#3465A4">[i]</font> Fixed in: 4.3.4
- <font color="#CC0000">[!]</font> Title: WordPress 4.2-4.5.2 - Authenticated Attachment Name Stored XSS
- Reference: https://wpvulndb.com/vulnerabilities/8518
- Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
- Reference: https://github.com/WordPress/WordPress/commit/4372cdf45d0f49c74bbd4d60db7281de83e32648
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5833
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5834
- <font color="#3465A4">[i]</font> Fixed in: 4.3.5
- <font color="#CC0000">[!]</font> Title: WordPress 3.6-4.5.2 - Authenticated Revision History Information Disclosure
- Reference: https://wpvulndb.com/vulnerabilities/8519
- Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
- Reference: https://github.com/WordPress/WordPress/commit/a2904cc3092c391ac7027bc87f7806953d1a25a1
- Reference: https://www.wordfence.com/blog/2016/06/wordpress-core-vulnerability-bypass-password-protected-posts/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5835
- <font color="#3465A4">[i]</font> Fixed in: 4.3.5
- <font color="#CC0000">[!]</font> Title: WordPress 2.6.0-4.5.2 - Unauthorized Category Removal from Post
- Reference: https://wpvulndb.com/vulnerabilities/8520
- Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
- Reference: https://github.com/WordPress/WordPress/commit/6d05c7521baa980c4efec411feca5e7fab6f307c
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5837
- <font color="#3465A4">[i]</font> Fixed in: 4.3.5
- <font color="#CC0000">[!]</font> Title: WordPress 2.5-4.6 - Authenticated Stored Cross-Site Scripting via Image Filename
- Reference: https://wpvulndb.com/vulnerabilities/8615
- Reference: https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/c9e60dab176635d4bfaaf431c0ea891e4726d6e0
- Reference: https://sumofpwn.nl/advisory/2016/persistent_cross_site_scripting_vulnerability_in_wordpress_due_to_unsafe_processing_of_file_names.html
- Reference: http://seclists.org/fulldisclosure/2016/Sep/6
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7168
- <font color="#3465A4">[i]</font> Fixed in: 4.3.6
- <font color="#CC0000">[!]</font> Title: WordPress 2.8-4.6 - Path Traversal in Upgrade Package Uploader
- Reference: https://wpvulndb.com/vulnerabilities/8616
- Reference: https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/54720a14d85bc1197ded7cb09bd3ea790caa0b6e
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7169
- <font color="#3465A4">[i]</font> Fixed in: 4.3.6
- <font color="#CC0000">[!]</font> Title: WordPress 4.3-4.7 - Remote Code Execution (RCE) in PHPMailer
- Reference: https://wpvulndb.com/vulnerabilities/8714
- Reference: https://www.wordfence.com/blog/2016/12/phpmailer-vulnerability/
- Reference: https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/24767c76d359231642b0ab48437b64e8c6c7f491
- Reference: http://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html
- Reference: https://www.rapid7.com/db/modules/exploit/unix/webapp/wp_phpmailer_host_header
- <font color="#3465A4">[i]</font> Fixed in: 4.3.7
- <font color="#CC0000">[!]</font> Title: WordPress 2.9-4.7 - Authenticated Cross-Site scripting (XSS) in update-core.php
- Reference: https://wpvulndb.com/vulnerabilities/8716
- Reference: https://github.com/WordPress/WordPress/blob/c9ea1de1441bb3bda133bf72d513ca9de66566c2/wp-admin/update-core.php
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5488
- <font color="#3465A4">[i]</font> Fixed in: 4.3.7
- <font color="#CC0000">[!]</font> Title: WordPress 3.4-4.7 - Stored Cross-Site Scripting (XSS) via Theme Name fallback
- Reference: https://wpvulndb.com/vulnerabilities/8718
- Reference: https://www.mehmetince.net/low-severity-wordpress/
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/ce7fb2934dd111e6353784852de8aea2a938b359
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5490
- <font color="#3465A4">[i]</font> Fixed in: 4.3.7
- <font color="#CC0000">[!]</font> Title: WordPress <= 4.7 - Post via Email Checks mail.example.com by Default
- Reference: https://wpvulndb.com/vulnerabilities/8719
- Reference: https://github.com/WordPress/WordPress/commit/061e8788814ac87706d8b95688df276fe3c8596a
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5491
- <font color="#3465A4">[i]</font> Fixed in: 4.3.7
- <font color="#CC0000">[!]</font> Title: WordPress 2.8-4.7 - Accessibility Mode Cross-Site Request Forgery (CSRF)
- Reference: https://wpvulndb.com/vulnerabilities/8720
- Reference: https://github.com/WordPress/WordPress/commit/03e5c0314aeffe6b27f4b98fef842bf0fb00c733
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5492
- <font color="#3465A4">[i]</font> Fixed in: 4.3.7
- <font color="#CC0000">[!]</font> Title: WordPress 3.0-4.7 - Cryptographically Weak Pseudo-Random Number Generator (PRNG)
- Reference: https://wpvulndb.com/vulnerabilities/8721
- Reference: https://github.com/WordPress/WordPress/commit/cea9e2dc62abf777e06b12ec4ad9d1aaa49b29f4
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5493
- <font color="#3465A4">[i]</font> Fixed in: 4.3.7
- <font color="#CC0000">[!]</font> Title: WordPress 4.2.0-4.7.1 - Press This UI Available to Unauthorised Users
- Reference: https://wpvulndb.com/vulnerabilities/8729
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
- Reference: https://github.com/WordPress/WordPress/commit/21264a31e0849e6ff793a06a17de877dd88ea454
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5610
- <font color="#3465A4">[i]</font> Fixed in: 4.3.8
- <font color="#CC0000">[!]</font> Title: WordPress 3.5-4.7.1 - WP_Query SQL Injection
- Reference: https://wpvulndb.com/vulnerabilities/8730
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
- Reference: https://github.com/WordPress/WordPress/commit/85384297a60900004e27e417eac56d24267054cb
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5611
- <font color="#3465A4">[i]</font> Fixed in: 4.3.8
- <font color="#CC0000">[!]</font> Title: WordPress 4.3.0-4.7.1 - Cross-Site Scripting (XSS) in posts list table
- Reference: https://wpvulndb.com/vulnerabilities/8731
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
- Reference: https://github.com/WordPress/WordPress/commit/4482f9207027de8f36630737ae085110896ea849
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5612
- <font color="#3465A4">[i]</font> Fixed in: 4.3.8
- <font color="#CC0000">[!]</font> Title: WordPress 3.6.0-4.7.2 - Authenticated Cross-Site Scripting (XSS) via Media File Metadata
- Reference: https://wpvulndb.com/vulnerabilities/8765
- Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/28f838ca3ee205b6f39cd2bf23eb4e5f52796bd7
- Reference: https://sumofpwn.nl/advisory/2016/wordpress_audio_playlist_functionality_is_affected_by_cross_site_scripting.html
- Reference: http://seclists.org/oss-sec/2017/q1/563
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6814
- <font color="#3465A4">[i]</font> Fixed in: 4.3.9
- <font color="#CC0000">[!]</font> Title: WordPress 2.8.1-4.7.2 - Control Characters in Redirect URL Validation
- Reference: https://wpvulndb.com/vulnerabilities/8766
- Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/288cd469396cfe7055972b457eb589cea51ce40e
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6815
- <font color="#3465A4">[i]</font> Fixed in: 4.3.9
- <font color="#CC0000">[!]</font> Title: WordPress 4.0-4.7.2 - Authenticated Stored Cross-Site Scripting (XSS) in YouTube URL Embeds
- Reference: https://wpvulndb.com/vulnerabilities/8768
- Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/419c8d97ce8df7d5004ee0b566bc5e095f0a6ca8
- Reference: https://blog.sucuri.net/2017/03/stored-xss-in-wordpress-core.html
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6817
- <font color="#3465A4">[i]</font> Fixed in: 4.3.9
- <font color="#CC0000">[!]</font> Title: WordPress 4.2-4.7.2 - Press This CSRF DoS
- Reference: https://wpvulndb.com/vulnerabilities/8770
- Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/263831a72d08556bc2f3a328673d95301a152829
- Reference: https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_press_this_function_allows_dos.html
- Reference: http://seclists.org/oss-sec/2017/q1/562
- Reference: https://hackerone.com/reports/153093
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6819
- <font color="#3465A4">[i]</font> Fixed in: 4.3.9
- <font color="#CC0000">[!]</font> Title: WordPress 2.3-4.8.3 - Host Header Injection in Password Reset
- Reference: https://wpvulndb.com/vulnerabilities/8807
- Reference: https://exploitbox.io/vuln/WordPress-Exploit-4-7-Unauth-Password-Reset-0day-CVE-2017-8295.html
- Reference: http://blog.dewhurstsecurity.com/2017/05/04/exploitbox-wordpress-security-advisories.html
- Reference: https://core.trac.wordpress.org/ticket/25239
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8295
- <font color="#CC0000">[!]</font> Title: WordPress 2.7.0-4.7.4 - Insufficient Redirect Validation
- Reference: https://wpvulndb.com/vulnerabilities/8815
- Reference: https://github.com/WordPress/WordPress/commit/76d77e927bb4d0f87c7262a50e28d84e01fd2b11
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9066
- <font color="#3465A4">[i]</font> Fixed in: 4.3.11
- <font color="#CC0000">[!]</font> Title: WordPress 2.5.0-4.7.4 - Post Meta Data Values Improper Handling in XML-RPC
- Reference: https://wpvulndb.com/vulnerabilities/8816
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://github.com/WordPress/WordPress/commit/3d95e3ae816f4d7c638f40d3e936a4be19724381
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9062
- <font color="#3465A4">[i]</font> Fixed in: 4.3.11
- <font color="#CC0000">[!]</font> Title: WordPress 3.4.0-4.7.4 - XML-RPC Post Meta Data Lack of Capability Checks
- Reference: https://wpvulndb.com/vulnerabilities/8817
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://github.com/WordPress/WordPress/commit/e88a48a066ab2200ce3091b131d43e2fab2460a4
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9065
- <font color="#3465A4">[i]</font> Fixed in: 4.3.11
- <font color="#CC0000">[!]</font> Title: WordPress 2.5.0-4.7.4 - Filesystem Credentials Dialog CSRF
- Reference: https://wpvulndb.com/vulnerabilities/8818
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://github.com/WordPress/WordPress/commit/38347d7c580be4cdd8476e4bbc653d5c79ed9b67
- Reference: https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_connection_information.html
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9064
- <font color="#3465A4">[i]</font> Fixed in: 4.3.11
- <font color="#CC0000">[!]</font> Title: WordPress 3.3-4.7.4 - Large File Upload Error XSS
- Reference: https://wpvulndb.com/vulnerabilities/8819
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://github.com/WordPress/WordPress/commit/8c7ea71edbbffca5d9766b7bea7c7f3722ffafa6
- Reference: https://hackerone.com/reports/203515
- Reference: https://hackerone.com/reports/203515
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9061
- <font color="#3465A4">[i]</font> Fixed in: 4.3.11
- <font color="#CC0000">[!]</font> Title: WordPress 3.4.0-4.7.4 - Customizer XSS & CSRF
- Reference: https://wpvulndb.com/vulnerabilities/8820
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://github.com/WordPress/WordPress/commit/3d10fef22d788f29aed745b0f5ff6f6baea69af3
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9063
- <font color="#3465A4">[i]</font> Fixed in: 4.3.11
- <font color="#CC0000">[!]</font> Title: WordPress 2.3.0-4.8.1 - $wpdb->prepare() potential SQL Injection
- Reference: https://wpvulndb.com/vulnerabilities/8905
- Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
- Reference: https://github.com/WordPress/WordPress/commit/fc930d3daed1c3acef010d04acc2c5de93cd18ec
- <font color="#3465A4">[i]</font> Fixed in: 4.3.12
- <font color="#CC0000">[!]</font> Title: WordPress 2.3.0-4.7.4 - Authenticated SQL injection
- Reference: https://wpvulndb.com/vulnerabilities/8906
- Reference: https://medium.com/websec/wordpress-sqli-bbb2afcc8e94
- Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
- Reference: https://wpvulndb.com/vulnerabilities/8905
- <font color="#3465A4">[i]</font> Fixed in: 4.7.5
- <font color="#CC0000">[!]</font> Title: WordPress 2.9.2-4.8.1 - Open Redirect
- Reference: https://wpvulndb.com/vulnerabilities/8910
- Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
- Reference: https://core.trac.wordpress.org/changeset/41398
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14725
- <font color="#3465A4">[i]</font> Fixed in: 4.3.12
- <font color="#CC0000">[!]</font> Title: WordPress 3.0-4.8.1 - Path Traversal in Unzipping
- Reference: https://wpvulndb.com/vulnerabilities/8911
- Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
- Reference: https://core.trac.wordpress.org/changeset/41457
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14719
- <font color="#3465A4">[i]</font> Fixed in: 4.3.12
- <font color="#CC0000">[!]</font> Title: WordPress 4.2.3-4.8.1 - Authenticated Cross-Site Scripting (XSS) in Visual Editor
- Reference: https://wpvulndb.com/vulnerabilities/8914
- Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
- Reference: https://core.trac.wordpress.org/changeset/41395
- Reference: https://blog.sucuri.net/2017/09/stored-cross-site-scripting-vulnerability-in-wordpress-4-8-1.html
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14726
- <font color="#3465A4">[i]</font> Fixed in: 4.3.12
- <font color="#CC0000">[!]</font> Title: WordPress <= 4.8.2 - $wpdb->prepare() Weakness
- Reference: https://wpvulndb.com/vulnerabilities/8941
- Reference: https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/
- Reference: https://github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167d
- Reference: https://twitter.com/ircmaxell/status/923662170092638208
- Reference: https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16510
- <font color="#3465A4">[i]</font> Fixed in: 4.3.13
- <font color="#CC0000">[!]</font> Title: WordPress 2.8.6-4.9 - Authenticated JavaScript File Upload
- Reference: https://wpvulndb.com/vulnerabilities/8966
- Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/67d03a98c2cae5f41843c897f206adde299b0509
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17092
- <font color="#3465A4">[i]</font> Fixed in: 4.3.14
- <font color="#CC0000">[!]</font> Title: WordPress 1.5.0-4.9 - RSS and Atom Feed Escaping
- Reference: https://wpvulndb.com/vulnerabilities/8967
- Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/f1de7e42df29395c3314bf85bff3d1f4f90541de
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17094
- <font color="#3465A4">[i]</font> Fixed in: 4.3.14
- <font color="#CC0000">[!]</font> Title: WordPress 4.3.0-4.9 - HTML Language Attribute Escaping
- Reference: https://wpvulndb.com/vulnerabilities/8968
- Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/3713ac5ebc90fb2011e98dfd691420f43da6c09a
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17093
- <font color="#3465A4">[i]</font> Fixed in: 4.3.14
- <font color="#CC0000">[!]</font> Title: WordPress 3.7-4.9 - 'newbloguser' Key Weak Hashing
- Reference: https://wpvulndb.com/vulnerabilities/8969
- Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/eaf1cfdc1fe0bdffabd8d879c591b864d833326c
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17091
- <font color="#3465A4">[i]</font> Fixed in: 4.3.14
- <font color="#4E9A06">[+]</font> WordPress theme in use: twentyfourteen - v1.5
- <font color="#4E9A06">[+]</font> Name: twentyfourteen - v1.5
- | Last updated: 2017-11-16T00:00:00.000Z
- | Location: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/
- | Readme: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/readme.txt
- <font color="#C4A000">[!]</font> The version is out of date, the latest version is 2.1
- | Style URL: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/style.css
- | Theme Name: Twenty Fourteen
- | Theme URI: https://wordpress.org/themes/twentyfourteen/
- | Description: In 2014, our default theme lets you create a responsive magazine website with a sleek, modern des...
- | Author: the WordPress team
- | Author URI: https://wordpress.org/
- <font color="#4E9A06">[+]</font> Enumerating plugins from passive detection ...
- | 1 plugin found:
- <font color="#4E9A06">[+]</font> Name: wordpress-seo - v2.3.5
- | Last updated: 2017-12-05T11:24:00.000Z
- | Location: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/
- | Readme: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/readme.txt
- | Changelog: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/changelog.txt
- <font color="#C4A000">[!]</font> The version is out of date, the latest version is 5.9.1
- <font color="#CC0000">[!]</font> Title: Yoast SEO <= 3.2.4 - Subscriber Settings Sensitive Data Exposure
- Reference: https://wpvulndb.com/vulnerabilities/8487
- Reference: https://www.wordfence.com/blog/2016/05/yoast-seo-vulnerability/
- <font color="#3465A4">[i]</font> Fixed in: 3.2.5
- <font color="#CC0000">[!]</font> Title: Yoast SEO <= 3.2.5 - Unspecified Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8569
- Reference: https://wordpress.org/plugins/wordpress-seo/changelog/
- <font color="#3465A4">[i]</font> Fixed in: 3.3.0
- <font color="#CC0000">[!]</font> Title: Yoast SEO <= 3.4.0 - Authenticated Stored Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8583
- Reference: https://plugins.trac.wordpress.org/changeset/1466243/wordpress-seo
- <font color="#3465A4">[i]</font> Fixed in: 3.4.1
- <font color="#CC0000">[!]</font> Title: Yoast SEO <= 5.7.1 - Unauthenticated Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8960
- Reference: https://plugins.trac.wordpress.org/changeset/1766831/wordpress-seo/trunk/admin/google_search_console/class-gsc-table.php
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16842
- <font color="#3465A4">[i]</font> Fixed in: 5.8
- <font color="#4E9A06">[+]</font> Enumerating usernames ...
- <font color="#4E9A06">[+]</font> Identified the following 1 user/s:
- +----+-------+---------------------------------+
- | Id | Login | Name |
- +----+-------+---------------------------------+
- | 1 | admin | admin, Autor w serwisie Kamillo |
- +----+-------+---------------------------------+
- <font color="#C4A000">[!]</font> Default first WordPress username 'admin' is still used
- <font color="#4E9A06">[+]</font> Finished: Sat Dec 16 23:56:31 2017
- <font color="#4E9A06">[+]</font> Requests Done: 93
- <font color="#4E9A06">[+]</font> Memory used: 36.223 MB
- <font color="#4E9A06">[+]</font> Elapsed time: 00:00:24
- </pre>
- [+] robots.txt available under: 'http://kamillotv.wex.pl/robots.txt'
- [!] The WordPress 'http://kamillotv.wex.pl/readme.html' file exists exposing a version number
- [+] Interesting header: SERVER: nginx
- [+] Interesting header: X-CACHE-STATUS: HIT
- [+] XML-RPC Interface available under: http://kamillotv.wex.pl/xmlrpc.php
- [+] WordPress version 4.3.1 (Released on 2015-09-15) identified from advanced fingerprinting, meta generator, rss generator, rdf generator, atom generator, readme, links opml
- [!] 44 vulnerabilities identified from the version number
- [!] Title: WordPress 3.7-4.4 - Authenticated Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8358
- Reference: https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/7ab65139c6838910426567849c7abed723932b87
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1564
- [i] Fixed in: 4.3.2
- [!] Title: WordPress 3.7-4.4 - Authenticated Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8358
- Reference: https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/7ab65139c6838910426567849c7abed723932b87
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1564
- [i] Fixed in: 4.3.2
- [!] Title: WordPress 3.7-4.4.1 - Local URIs Server Side Request Forgery (SSRF)
- Reference: https://wpvulndb.com/vulnerabilities/8376
- Reference: https://wordpress.org/news/2016/02/wordpress-4-4-2-security-and-maintenance-release/
- Reference: https://core.trac.wordpress.org/changeset/36435
- Reference: https://hackerone.com/reports/110801
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2222
- [i] Fixed in: 4.3.3
- [!] Title: WordPress 3.7-4.4.1 - Open Redirect
- Reference: https://wpvulndb.com/vulnerabilities/8377
- Reference: https://wordpress.org/news/2016/02/wordpress-4-4-2-security-and-maintenance-release/
- Reference: https://core.trac.wordpress.org/changeset/36444
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2221
- [i] Fixed in: 4.3.3
- [!] Title: WordPress <= 4.4.2 - SSRF Bypass using Octal & Hexedecimal IP addresses
- Reference: https://wpvulndb.com/vulnerabilities/8473
- Reference: https://codex.wordpress.org/Version_4.5
- Reference: https://github.com/WordPress/WordPress/commit/af9f0520875eda686fd13a427fd3914d7aded049
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4029
- [i] Fixed in: 4.5
- [!] Title: WordPress <= 4.4.2 - Reflected XSS in Network Settings
- Reference: https://wpvulndb.com/vulnerabilities/8474
- Reference: https://codex.wordpress.org/Version_4.5
- Reference: https://github.com/WordPress/WordPress/commit/cb2b3ed3c7d68f6505bfb5c90257e6aaa3e5fcb9
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6634
- [i] Fixed in: 4.5
- [!] Title: WordPress <= 4.4.2 - Script Compression Option CSRF
- Reference: https://wpvulndb.com/vulnerabilities/8475
- Reference: https://codex.wordpress.org/Version_4.5
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6635
- [i] Fixed in: 4.5
- [!] Title: WordPress 4.2-4.5.1 - MediaElement.js Reflected Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8488
- Reference: https://wordpress.org/news/2016/05/wordpress-4-5-2/
- Reference: https://github.com/WordPress/WordPress/commit/a493dc0ab5819c8b831173185f1334b7c3e02e36
- Reference: https://gist.github.com/cure53/df34ea68c26441f3ae98f821ba1feb9c
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4567
- [i] Fixed in: 4.5.2
- [!] Title: WordPress <= 4.5.1 - Pupload Same Origin Method Execution (SOME)
- Reference: https://wpvulndb.com/vulnerabilities/8489
- Reference: https://wordpress.org/news/2016/05/wordpress-4-5-2/
- Reference: https://github.com/WordPress/WordPress/commit/c33e975f46a18f5ad611cf7e7c24398948cecef8
- Reference: https://gist.github.com/cure53/09a81530a44f6b8173f545accc9ed07e
- Reference: http://avlidienbrunn.com/wp_some_loader.php
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4566
- [i] Fixed in: 4.3.4
- [!] Title: WordPress 4.2-4.5.2 - Authenticated Attachment Name Stored XSS
- Reference: https://wpvulndb.com/vulnerabilities/8518
- Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
- Reference: https://github.com/WordPress/WordPress/commit/4372cdf45d0f49c74bbd4d60db7281de83e32648
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5833
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5834
- [i] Fixed in: 4.3.5
- [!] Title: WordPress 3.6-4.5.2 - Authenticated Revision History Information Disclosure
- Reference: https://wpvulndb.com/vulnerabilities/8519
- Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
- Reference: https://github.com/WordPress/WordPress/commit/a2904cc3092c391ac7027bc87f7806953d1a25a1
- Reference: https://www.wordfence.com/blog/2016/06/wordpress-core-vulnerability-bypass-password-protected-posts/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5835
- [i] Fixed in: 4.3.5
- [!] Title: WordPress 2.6.0-4.5.2 - Unauthorized Category Removal from Post
- Reference: https://wpvulndb.com/vulnerabilities/8520
- Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
- Reference: https://github.com/WordPress/WordPress/commit/6d05c7521baa980c4efec411feca5e7fab6f307c
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5837
- [i] Fixed in: 4.3.5
- [!] Title: WordPress 2.5-4.6 - Authenticated Stored Cross-Site Scripting via Image Filename
- Reference: https://wpvulndb.com/vulnerabilities/8615
- Reference: https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/c9e60dab176635d4bfaaf431c0ea891e4726d6e0
- Reference: https://sumofpwn.nl/advisory/2016/persistent_cross_site_scripting_vulnerability_in_wordpress_due_to_unsafe_processing_of_file_names.html
- Reference: http://seclists.org/fulldisclosure/2016/Sep/6
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7168
- [i] Fixed in: 4.3.6
- [!] Title: WordPress 2.8-4.6 - Path Traversal in Upgrade Package Uploader
- Reference: https://wpvulndb.com/vulnerabilities/8616
- Reference: https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/54720a14d85bc1197ded7cb09bd3ea790caa0b6e
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7169
- [i] Fixed in: 4.3.6
- [!] Title: WordPress 4.3-4.7 - Remote Code Execution (RCE) in PHPMailer
- Reference: https://wpvulndb.com/vulnerabilities/8714
- Reference: https://www.wordfence.com/blog/2016/12/phpmailer-vulnerability/
- Reference: https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/24767c76d359231642b0ab48437b64e8c6c7f491
- Reference: http://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html
- Reference: https://www.rapid7.com/db/modules/exploit/unix/webapp/wp_phpmailer_host_header
- [i] Fixed in: 4.3.7
- [!] Title: WordPress 2.9-4.7 - Authenticated Cross-Site scripting (XSS) in update-core.php
- Reference: https://wpvulndb.com/vulnerabilities/8716
- Reference: https://github.com/WordPress/WordPress/blob/c9ea1de1441bb3bda133bf72d513ca9de66566c2/wp-admin/update-core.php
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5488
- [i] Fixed in: 4.3.7
- [!] Title: WordPress 3.4-4.7 - Stored Cross-Site Scripting (XSS) via Theme Name fallback
- Reference: https://wpvulndb.com/vulnerabilities/8718
- Reference: https://www.mehmetince.net/low-severity-wordpress/
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/ce7fb2934dd111e6353784852de8aea2a938b359
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5490
- [i] Fixed in: 4.3.7
- [!] Title: WordPress <= 4.7 - Post via Email Checks mail.example.com by Default
- Reference: https://wpvulndb.com/vulnerabilities/8719
- Reference: https://github.com/WordPress/WordPress/commit/061e8788814ac87706d8b95688df276fe3c8596a
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5491
- [i] Fixed in: 4.3.7
- [!] Title: WordPress 2.8-4.7 - Accessibility Mode Cross-Site Request Forgery (CSRF)
- Reference: https://wpvulndb.com/vulnerabilities/8720
- Reference: https://github.com/WordPress/WordPress/commit/03e5c0314aeffe6b27f4b98fef842bf0fb00c733
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5492
- [i] Fixed in: 4.3.7
- [!] Title: WordPress 3.0-4.7 - Cryptographically Weak Pseudo-Random Number Generator (PRNG)
- Reference: https://wpvulndb.com/vulnerabilities/8721
- Reference: https://github.com/WordPress/WordPress/commit/cea9e2dc62abf777e06b12ec4ad9d1aaa49b29f4
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5493
- [i] Fixed in: 4.3.7
- [!] Title: WordPress 4.2.0-4.7.1 - Press This UI Available to Unauthorised Users
- Reference: https://wpvulndb.com/vulnerabilities/8729
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
- Reference: https://github.com/WordPress/WordPress/commit/21264a31e0849e6ff793a06a17de877dd88ea454
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5610
- [i] Fixed in: 4.3.8
- [!] Title: WordPress 3.5-4.7.1 - WP_Query SQL Injection
- Reference: https://wpvulndb.com/vulnerabilities/8730
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
- Reference: https://github.com/WordPress/WordPress/commit/85384297a60900004e27e417eac56d24267054cb
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5611
- [i] Fixed in: 4.3.8
- [!] Title: WordPress 4.3.0-4.7.1 - Cross-Site Scripting (XSS) in posts list table
- Reference: https://wpvulndb.com/vulnerabilities/8731
- Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
- Reference: https://github.com/WordPress/WordPress/commit/4482f9207027de8f36630737ae085110896ea849
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5612
- [i] Fixed in: 4.3.8
- [!] Title: WordPress 3.6.0-4.7.2 - Authenticated Cross-Site Scripting (XSS) via Media File Metadata
- Reference: https://wpvulndb.com/vulnerabilities/8765
- Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/28f838ca3ee205b6f39cd2bf23eb4e5f52796bd7
- Reference: https://sumofpwn.nl/advisory/2016/wordpress_audio_playlist_functionality_is_affected_by_cross_site_scripting.html
- Reference: http://seclists.org/oss-sec/2017/q1/563
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6814
- [i] Fixed in: 4.3.9
- [!] Title: WordPress 2.8.1-4.7.2 - Control Characters in Redirect URL Validation
- Reference: https://wpvulndb.com/vulnerabilities/8766
- Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/288cd469396cfe7055972b457eb589cea51ce40e
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6815
- [i] Fixed in: 4.3.9
- [!] Title: WordPress 4.0-4.7.2 - Authenticated Stored Cross-Site Scripting (XSS) in YouTube URL Embeds
- Reference: https://wpvulndb.com/vulnerabilities/8768
- Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/419c8d97ce8df7d5004ee0b566bc5e095f0a6ca8
- Reference: https://blog.sucuri.net/2017/03/stored-xss-in-wordpress-core.html
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6817
- [i] Fixed in: 4.3.9
- [!] Title: WordPress 4.2-4.7.2 - Press This CSRF DoS
- Reference: https://wpvulndb.com/vulnerabilities/8770
- Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/263831a72d08556bc2f3a328673d95301a152829
- Reference: https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_press_this_function_allows_dos.html
- Reference: http://seclists.org/oss-sec/2017/q1/562
- Reference: https://hackerone.com/reports/153093
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6819
- [i] Fixed in: 4.3.9
- [!] Title: WordPress 2.3-4.8.3 - Host Header Injection in Password Reset
- Reference: https://wpvulndb.com/vulnerabilities/8807
- Reference: https://exploitbox.io/vuln/WordPress-Exploit-4-7-Unauth-Password-Reset-0day-CVE-2017-8295.html
- Reference: http://blog.dewhurstsecurity.com/2017/05/04/exploitbox-wordpress-security-advisories.html
- Reference: https://core.trac.wordpress.org/ticket/25239
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8295
- [!] Title: WordPress 2.7.0-4.7.4 - Insufficient Redirect Validation
- Reference: https://wpvulndb.com/vulnerabilities/8815
- Reference: https://github.com/WordPress/WordPress/commit/76d77e927bb4d0f87c7262a50e28d84e01fd2b11
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9066
- [i] Fixed in: 4.3.11
- [!] Title: WordPress 2.5.0-4.7.4 - Post Meta Data Values Improper Handling in XML-RPC
- Reference: https://wpvulndb.com/vulnerabilities/8816
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://github.com/WordPress/WordPress/commit/3d95e3ae816f4d7c638f40d3e936a4be19724381
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9062
- [i] Fixed in: 4.3.11
- [!] Title: WordPress 3.4.0-4.7.4 - XML-RPC Post Meta Data Lack of Capability Checks
- Reference: https://wpvulndb.com/vulnerabilities/8817
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://github.com/WordPress/WordPress/commit/e88a48a066ab2200ce3091b131d43e2fab2460a4
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9065
- [i] Fixed in: 4.3.11
- [!] Title: WordPress 2.5.0-4.7.4 - Filesystem Credentials Dialog CSRF
- Reference: https://wpvulndb.com/vulnerabilities/8818
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://github.com/WordPress/WordPress/commit/38347d7c580be4cdd8476e4bbc653d5c79ed9b67
- Reference: https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_connection_information.html
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9064
- [i] Fixed in: 4.3.11
- [!] Title: WordPress 3.3-4.7.4 - Large File Upload Error XSS
- Reference: https://wpvulndb.com/vulnerabilities/8819
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://github.com/WordPress/WordPress/commit/8c7ea71edbbffca5d9766b7bea7c7f3722ffafa6
- Reference: https://hackerone.com/reports/203515
- Reference: https://hackerone.com/reports/203515
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9061
- [i] Fixed in: 4.3.11
- [!] Title: WordPress 3.4.0-4.7.4 - Customizer XSS & CSRF
- Reference: https://wpvulndb.com/vulnerabilities/8820
- Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
- Reference: https://github.com/WordPress/WordPress/commit/3d10fef22d788f29aed745b0f5ff6f6baea69af3
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9063
- [i] Fixed in: 4.3.11
- [!] Title: WordPress 2.3.0-4.8.1 - $wpdb->prepare() potential SQL Injection
- Reference: https://wpvulndb.com/vulnerabilities/8905
- Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
- Reference: https://github.com/WordPress/WordPress/commit/fc930d3daed1c3acef010d04acc2c5de93cd18ec
- [i] Fixed in: 4.3.12
- [!] Title: WordPress 2.3.0-4.7.4 - Authenticated SQL injection
- Reference: https://wpvulndb.com/vulnerabilities/8906
- Reference: https://medium.com/websec/wordpress-sqli-bbb2afcc8e94
- Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
- Reference: https://wpvulndb.com/vulnerabilities/8905
- [i] Fixed in: 4.7.5
- [!] Title: WordPress 2.9.2-4.8.1 - Open Redirect
- Reference: https://wpvulndb.com/vulnerabilities/8910
- Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
- Reference: https://core.trac.wordpress.org/changeset/41398
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14725
- [i] Fixed in: 4.3.12
- [!] Title: WordPress 3.0-4.8.1 - Path Traversal in Unzipping
- Reference: https://wpvulndb.com/vulnerabilities/8911
- Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
- Reference: https://core.trac.wordpress.org/changeset/41457
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14719
- [i] Fixed in: 4.3.12
- [!] Title: WordPress 4.2.3-4.8.1 - Authenticated Cross-Site Scripting (XSS) in Visual Editor
- Reference: https://wpvulndb.com/vulnerabilities/8914
- Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
- Reference: https://core.trac.wordpress.org/changeset/41395
- Reference: https://blog.sucuri.net/2017/09/stored-cross-site-scripting-vulnerability-in-wordpress-4-8-1.html
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14726
- [i] Fixed in: 4.3.12
- [!] Title: WordPress <= 4.8.2 - $wpdb->prepare() Weakness
- Reference: https://wpvulndb.com/vulnerabilities/8941
- Reference: https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/
- Reference: https://github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167d
- Reference: https://twitter.com/ircmaxell/status/923662170092638208
- Reference: https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16510
- [i] Fixed in: 4.3.13
- [!] Title: WordPress 2.8.6-4.9 - Authenticated JavaScript File Upload
- Reference: https://wpvulndb.com/vulnerabilities/8966
- Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/67d03a98c2cae5f41843c897f206adde299b0509
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17092
- [i] Fixed in: 4.3.14
- [!] Title: WordPress 1.5.0-4.9 - RSS and Atom Feed Escaping
- Reference: https://wpvulndb.com/vulnerabilities/8967
- Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/f1de7e42df29395c3314bf85bff3d1f4f90541de
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17094
- [i] Fixed in: 4.3.14
- [!] Title: WordPress 4.3.0-4.9 - HTML Language Attribute Escaping
- Reference: https://wpvulndb.com/vulnerabilities/8968
- Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/3713ac5ebc90fb2011e98dfd691420f43da6c09a
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17093
- [i] Fixed in: 4.3.14
- [!] Title: WordPress 3.7-4.9 - 'newbloguser' Key Weak Hashing
- Reference: https://wpvulndb.com/vulnerabilities/8969
- Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
- Reference: https://github.com/WordPress/WordPress/commit/eaf1cfdc1fe0bdffabd8d879c591b864d833326c
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17091
- [i] Fixed in: 4.3.14
- [+] WordPress theme in use: twentyfourteen - v1.5
- [+] Name: twentyfourteen - v1.5
- | Last updated: 2017-11-16T00:00:00.000Z
- | Location: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/
- | Readme: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/readme.txt
- [!] The version is out of date, the latest version is 2.1
- | Style URL: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/style.css
- | Theme Name: Twenty Fourteen
- | Theme URI: https://wordpress.org/themes/twentyfourteen/
- | Description: In 2014, our default theme lets you create a responsive magazine website with a sleek, modern des...
- | Author: the WordPress team
- | Author URI: https://wordpress.org/
- [+] Enumerating plugins from passive detection ...
- | 1 plugin found:
- [+] Name: wordpress-seo - v2.3.5
- | Last updated: 2017-12-05T11:24:00.000Z
- | Location: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/
- | Readme: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/readme.txt
- | Changelog: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/changelog.txt
- [!] The version is out of date, the latest version is 5.9.1
- [!] Title: Yoast SEO <= 3.2.4 - Subscriber Settings Sensitive Data Exposure
- Reference: https://wpvulndb.com/vulnerabilities/8487
- Reference: https://www.wordfence.com/blog/2016/05/yoast-seo-vulnerability/
- [i] Fixed in: 3.2.5
- [!] Title: Yoast SEO <= 3.2.5 - Unspecified Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8569
- Reference: https://wordpress.org/plugins/wordpress-seo/changelog/
- [i] Fixed in: 3.3.0
- [!] Title: Yoast SEO <= 3.4.0 - Authenticated Stored Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8583
- Reference: https://plugins.trac.wordpress.org/changeset/1466243/wordpress-seo
- [i] Fixed in: 3.4.1
- [!] Title: Yoast SEO <= 5.7.1 - Unauthenticated Cross-Site Scripting (XSS)
- Reference: https://wpvulndb.com/vulnerabilities/8960
- Reference: https://plugins.trac.wordpress.org/changeset/1766831/wordpress-seo/trunk/admin/google_search_console/class-gsc-table.php
- Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16842
- [i] Fixed in: 5.8
- [+] Enumerating usernames ...
- [+] Identified the following 1 user/s:
- +----+-------+---------------------------------+
- | Id | Login | Name |
- +----+-------+---------------------------------+
- | 1 | admin | admin, Autor w serwisie Kamillo |
- +----+-------+---------------------------------+
- [!] Default first WordPress username 'admin' is still used
- [+] Finished: Sat Dec 16 23:56:31 2017
- [+] Requests Done: 93
- [+] Memory used: 36.223 MB
- [+] Elapsed time: 00:00:24
Advertisement
Add Comment
Please, Sign In to add comment