WordPress < 3.1.3 Multiple Vulnerabilities

Critical Nessus Network Monitor Plugin ID 9108


The remote server is hosting an outdated installation of WordPress that is vulnerable to multiple attack vectors.


Versions of WordPress prior to 3.1.3 are susceptible to the following vulnerabilities :

- An unspecified flaw exists related to media security. (CVE-2011-3122)
- An unspecified flaw exists related to security hardening. (CVE-2011-3125)
- A flaw exists that allows remote attackers to determine usernames of non-authors via canonical redirects. (CVE-2011-3126)
- A flaw exists which fails to prevent rendering for admin or login pages inside a frame in a third-party HTML document. A remote attacker may exploit this to conduct clickjacking attacks via a crafted web site. (CVE-2011-3127)
- A flaw exists that treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to 'wp-includes/post.php'. (CVE-2011-3128)
- An unspecified flaw exists related to file upload functionaliy. (CVE-2011-3129)
- An unspecified flaw exists in 'wp-includes/taxonomy.php' related to taxonomy query hardening which may allow an attacker to conduct an SQL injection attack. (CVE-2011-3130)


Upgrade to WordPress 3.3.2, or later.

See Also


Plugin Details

Severity: Critical

ID: 9108

File Name: 9108.prm

Family: CGI

Published: 2016/02/26

Modified: 2016/11/23

Dependencies: 9035, 9036

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C


Base Score: 9.8

Temporal Score: 9.4


Temporal Vector: CVSS3#E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:wordpress:wordpress

Patch Publication Date: 2011/05/25

Vulnerability Publication Date: 2011/05/25

Reference Information

CVE: CVE-2011-3122, CVE-2011-3125, CVE-2011-3126, CVE-2011-3127, CVE-2011-3128, CVE-2011-3129, CVE-2011-3130

BID: 47709, 47995, 49730