Codex

CVEs

CVE stands for Common Vulnerabilities and Exposures, which is an industry standard way to track security issues in software applications. They are tracked centrally in the National Vulnerability Database run by the Department of Homeland Security.

Although many CVEs mention WordPress, only a few are applicable. Here is a list of CVEs that mention WordPress, organized by year, and whether the CVE impacts WordPress Plugins, the core programming, WordPress.com, or another aspect of WordPress, as well as which version of WordPress was impacted.

In terms of security of your WordPress blog, being on the latest version of WordPress is all you need. WordPress generally fixes vulnerabilities and releases an upgrade or security update version before they become public and are issued a CVE.

2008

42 total CVEs, 33 apply to plugins, 3 apply to core, 2 to legacy, and 4 are invalid.

CVE ID Date Impact Notes
CVE-2008-2510 2008-05-29 Plugin  
CVE-2008-2392 2008-05-21 Invalid "Admin" user has ability to edit plugins and upload files if file permissions allow- this is intentional.
CVE-2008-2146 2008-05-12 Invalid Describes a known issue in WordPress 2.2, which was released more than a year before. (Covered by previous CVE.) The problem described was fixed 9 months before this report.
CVE-2008-2068 2008-05-02 Core "Unspecified vectors" were never publicly reported, but fixed in 2.5.1.
CVE-2008-2034 2008-04-30 Plugin
CVE-2008-1930 2008-04-28 Core Cookie-based cryptographic splicing attack. Fixed in 2.5.1 prior to disclosure.
CVE-2008-2146 2008-04-27 Plugin  
CVE-2008-1982 2008-04-02 Plugin  
CVE-2008-1304 2008-03-12 WordPress.com XSS in invite system on WordPress.com, did not apply to WordPress.org blogs at all.
CVE-2008-1060 2008-02-28 Plugin  
CVE-2008-1059 2008-02-28 Plugin  
CVE-2008-0939 2008-02-25 Plugin  
CVE-2008-0845 2008-02-20 Plugin  
CVE-2008-0837 2008-02-20 Plugin  
CVE-2008-0691 2008-02-11 Plugin  
CVE-2008-0683 2008-02-11 Plugin  
CVE-2008-0682 2008-02-11 Plugin  
CVE-2008-0664 2008-02-07 Core If registration was enabled, an undisclosed vulnerability in XML-RPC. Fixed by 2.5 prior to disclosure.
CVE-2008-0618 2008-02-06 Plugin  
CVE-2008-0617 2008-02-06 Plugin  
CVE-2008-0616 2008-02-06 Plugin  
CVE-2008-0615 2008-02-06 Plugin  
CVE-2008-0560 2008-02-04 Plugin  
CVE-2008-0520 2008-01-31 Plugin  
CVE-2008-0508 2008-01-31 Plugin  
CVE-2008-0507 2008-01-31 Plugin  
CVE-2008-0491 2008-01-30 Plugin  
CVE-2008-0490 2008-01-30 Plugin  
CVE-2008-0388 2008-01-22 Plugin  
CVE-2008-0222 2008-01-10 Plugin  
CVE-2008-0206 2008-01-09 Plugin  
CVE-2008-0205 2008-01-09 Plugin  
CVE-2008-0204 2008-01-09 Plugin  
CVE-2008-0198 2008-01-09 Plugin  
CVE-2008-0197 2008-01-09 Plugin  
CVE-2008-0196 2008-01-09 Legacy Core Problem in legacy 2.0 branch of WordPress, not applicable to current versions.
CVE-2008-0195 2008-01-09 Legacy Core Disclosure in legacy 2.0 branch of WordPress, not applicable to current versions.
CVE-2008-0194 2008-01-09 Plugin Fixed in version 2.1.0 of this plugin, released 7 months prior to this CVE
CVE-2008-0193 2008-01-09 Plugin Fixed in version 2.1.0 of this plugin, released 7 months prior to this CVE
CVE-2008-0192 2008-01-09 Invalid Problem already fixed by 2.0.10 release 9 months before this CVE.
CVE-2008-0191 2008-01-09 Invalid Could not recreate in current release (2.3.2) at that time