Vuln Xss Pada Suati Web
Vuln Xss Pada Suati Web
47 ) is hosted on
3.9.2 1 No Yes
No Yes
Well done! The WordPress admin console is not accessible on the default URL. It’s a
great way to prevent brute force attacks.
Blacklisted (safe)
HTTPS (on)
https://bbg.co.id/feed/, <generator>http://wordpress.org/?v=3.9.2</generator>
https://bbg.co.id/comments/feed/, <generator>http://wordpress.org/?
v=3.9.2</generator>
https://bbg.co.id/home/feed/, <generator>http://wordpress.org/?
v=3.9.2</generator>
https://wpvulndb.com/vulnerabilities/8ee5c93f-6dd4-4001-b805-0d62a2475932
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2012-5868
http://whiteoaksecurity.com/blog/2012/12/17/cve-2012-5868-wordpress-342-
sessions-not-terminated-upon-explicit-user-logout
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/leveraging-lfi-
to-get-full-compromise-on-wordpress-sites/
https://wpvulndb.com/vulnerabilities/a30dff57-91a5-433e-8282-90d0115ddcca
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2014-9031
https://klikki.fi/adv/wordpress.html
https://wordpress.org/news/2014/11/wordpress-4-0-1/
https://klikki.fi/adv/wordpress_update.html
Fixed in 4.0.1
https://wpvulndb.com/vulnerabilities/aa6a0791-5d59-4c80-b943-bfec7fff7862
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2014-9034
http://www.behindthefirewalls.com/2014/11/wordpress-denial-of-service-
responsible-disclosure.html
https://wordpress.org/news/2014/11/wordpress-4-0-1/
https://wpvulndb.com/vulnerabilities/894714e0-e582-4ae8-86d2-9826604bd823
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2014-9038
https://www.securityfocus.com/bid/71234/
https://core.trac.wordpress.org/changeset/30444
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2014-9032
https://core.trac.wordpress.org/changeset/30422
Fixed in 4.1.2
Fixed in 4.0.1
Fixed in 3.9.7
https://wpvulndb.com/vulnerabilities/0f027d7d-674b-4a63-9603-25ea68069c1d
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2015-5622
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2015-5623
https://wordpress.org/news/2015/07/wordpress-4-2-3/
https://twitter.com/klikkioy/status/624264122570526720
https://klikki.fi/adv/wordpress3.html
https://wpvulndb.com/vulnerabilities/0f027d7d-674b-4a63-9603-25ea68069c1d
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2015-5622
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2015-5623
https://wordpress.org/news/2015/07/wordpress-4-2-3/
https://twitter.com/klikkioy/status/624264122570526720
https://klikki.fi/adv/wordpress3.html
WordPress <= 4.2.3 - wp_untrash_post_comments SQL Injection
Fixed in 3.9.8
https://wpvulndb.com/vulnerabilities/b52728fa-c068-4098-b796-ce421f31bde5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2015-2213
https://github.com/WordPress/WordPress/commit/70128fe7605cb963a46815cf91b0a5934f70e
ff5
https://wpvulndb.com/vulnerabilities/3c4fe98d-04dd-4217-945d-11e06a173916
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2015-5730
https://core.trac.wordpress.org/changeset/33536
https://wpvulndb.com/vulnerabilities/32787617-081f-4743-a9a7-5dd6642308b2
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2015-5732
https://core.trac.wordpress.org/changeset/33529
WordPress <= 4.3 - Publish Post & Mark as Sticky Permission Issue
WordPress <= 4.4.2 - SSRF Bypass using Octal & Hexedecimal IP addresses
Fixed in 4.5
WordPress 3.4-4.7 - Stored Cross-Site Scripting (XSS) via Theme Name fallback
Fixed in 3.9.15
Fixed in 3.9.19
Fixed in 3.9.19
WordPress 3.3-4.7.4 - Large File Upload Error XSS
Fixed in 3.9.19
Fixed in 3.9.20
Fixed in 3.9.21
Fixed in 3.9.22
Fixed in 3.9.22
Fixed in 3.9.22
Fixed in 3.9.23
Fixed in 3.9.24
Fixed in 3.9.24
Fixed in 3.9.24
Fixed in 3.9.25
Fixed in 3.9.26
Fixed in 3.9.26
Fixed in 3.9.26
WordPress <= 5.0 - Cross-Site Scripting (XSS) that could affect plugins
Fixed in 3.9.26
Fixed in 3.9.26
Fixed in 3.9.26
Fixed in 3.9.27
Fixed in 3.9.29
Fixed in 3.9.29
Fixed in 3.9.29
Fixed in 3.9.29
Fixed in 3.9.29
Fixed in 3.9.30
Fixed in 3.9.30
WordPress <= 5.3 - Authenticated Stored XSS via Block Editor Content
Fixed in 3.9.30
Fixed in 3.9.30
Fixed in 3.9.31
Fixed in 3.9.31
Fixed in 3.9.31
Fixed in 3.9.31
Fixed in 3.9.32
Fixed in 3.9.32
Fixed in 3.9.32