|
#41391
|
Links to media in password protected pages
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
9 years ago
|
|
#63940
|
Prevent POST flood cache bypass attacks
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
10 months ago
|
|
#53994
|
REST API requests with session cookies but an invalid/missing nonce are considered authenticated for most of the request
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
5 years ago
|
|
#63259
|
Replace zxcvbn with zxcvbn-ts
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
15 months ago
|
|
#56860
|
Sodium Compat library is improperly loaded
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
20 months ago
|
|
#65574
|
Unsafe usage of href attribute in wp-admin/js/common.js
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
11 days ago
|
|
#65573
|
Unsafe usage of href attribute in wp-admin/js/link.js
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
11 days ago
|
|
#65572
|
Unsafe usage of href attribute in wp-admin/js/post.js
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
11 days ago
|
|
#62693
|
check if chmod is available to prevent Fatal Errors
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
19 months ago
|
|
#58679
|
meta key field in usermeta table should NOT use accent insensitive collations
|
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
|
11 months ago
|
|
#57447
|
wp_ajax_inline_save function does not check if post has "public" or "show_ui" enabled
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
|
4 years ago
|
|
#62384
|
.htaccess lacks
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
|
19 months ago
|
|
#58636
|
Automatic Sanitization of Nonces in wp_verify_nonce
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
|
3 years ago
|
|
#40237
|
Educate users about modern password best-practices
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
|
4 years ago
|
|
#51611
|
Escape echoing Core functions
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
|
6 years ago
|
|
#64481
|
Explore Sec-Fetch Headers as a Core-Supported CSRF Mitigation Mechanism
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
|
6 months ago
|
|
#43320
|
Harden API requests against man-in-the-middle attacks
|
|
low
|
minor
|
Awaiting Review
|
enhancement
|
|
8 years ago
|
|
#51159
|
Let's expand our context specific escaping methods for wp_json_encode().
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
|
6 months ago
|
|
#57424
|
Specific hook for Content Security Policy
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
|
4 years ago
|
|
#60470
|
Use `filter_input` instead of superglobals where possible
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
|
2 years ago
|
|
#36177
|
default htaccess should include security measures
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
|
19 months ago
|
|
#55514
|
2FA by default for WordPress
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
3 years ago
|
|
#43215
|
Allow wp_kses to pass allowed CSS properties
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
8 months ago
|
|
#53902
|
Automating the creation of inline javascript and inline stylesheet nonces or hashes
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
|
2 years ago
|
|
#65054
|
$_GET['pagenow'] and $_GET['widget'] unsanitized in dashboard AJAX handler
|
rajeshcp
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
11 days ago
|
|
#52333
|
Lack of the : entity on the list of allowed entity names in kses.php
|
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
has-patch
|
5 years ago
|
|
#65052
|
Nonce check order flaw in post-quickdraft-save
|
rajeshcp
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
8 weeks ago
|
|
#37264
|
Please do not chmod 666 the wp-config.php file on installation.
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
7 years ago
|
|
#53869
|
Post type / Taxonomy Label Hardening: Prevent Raw HTML tags in output / Media Library eval of HTML entities in label
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
5 years ago
|
|
#60864
|
URL sanitizing strips valid characters instead of encoding, documented use is invalid
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
6 months ago
|
|
#56521
|
wp_kses wp_kses_hair fails to allow a valueless attribute when is follwed by /
|
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
has-patch
|
4 years ago
|
|
#23165
|
Admin validation errors on form nonce element IDs (_wpnonce)
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
has-patch
|
5 years ago
|
|
#63329
|
Use check_ajax_referer() instead of check_admin_referer() for AJAX requests in media form handling.
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
has-patch
|
15 months ago
|
|
#65448
|
Use the new Uri\Rfc3986\Uri::parse in wp_parse_url() if PHP 8.5 is available
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
has-patch
|
3 weeks ago
|