Пожалуйста, обратите внимание, что пользователь заблокирован
Всем общий салам, ребят в теме только только совсем, только начал пробовать, нашел сайт который выдал вот такие уязвимости, подскажите что и как действовать дальше с ними, заранее всем огромное спасибо
| [!] Title: WordPress 4.7-5.7 - Authenticated Password Protected Pages Exposure
| [!] Title: WordPress 3.7 to 5.7.1 - Object Injection in PHPMailer
| [!] Title: WordPress 5.4 to 5.8 - Lodash Library Update
| [!] Title: WordPress 5.4 to 5.8 - Authenticated XSS in Block Editor
| [!] Title: WordPress 5.4 to 5.8 - Data Exposure via REST API
| [!] Title: WordPress < 5.8.2 - Expired DST Root CA X3 Certificate
| [!] Title: WordPress < 5.8 - Plugin Confusion
| [!] Title: WordPress < 5.8.3 - SQL Injection via WP_Query
| [!] Title: WordPress < 5.8.3 - Author+ Stored XSS via Post Slugs
| [!] Title: WordPress 4.1-5.8.2 - SQL Injection via WP_Meta_Query
| [!] Title: WordPress < 5.8.3 - Super Admin Object Injection in Multisites
| [!] Title: WordPress < 5.9.2 - Prototype Pollution in jQuery
| [!] Title: WP < 6.0.2 - Reflected Cross-Site Scripting
| [!] Title: WP < 6.0.2 - Authenticated Stored Cross-Site Scripting
| [!] Title: WP < 6.0.2 - SQLi via Link API
| [!] Title: WP < 6.0.3 - Stored XSS via wp-mail.php
| [!] Title: WP < 6.0.3 - Open Redirect via wp_nonce_ays
| [!] Title: WP < 6.0.3 - Email Address Disclosure via wp-mail.php
| [!] Title: WP < 6.0.3 - Reflected XSS via SQLi in Media Library
| [!] Title: WP < 6.0.3 - CSRF in wp-trackback.php
| [!] Title: WP < 6.0.3 - Stored XSS via the Customizer
| [!] Title: WP < 6.0.3 - Stored XSS via Comment Editing
| [!] Title: WP < 6.0.3 - Content from Multipart Emails Leaked
| [!] Title: WP < 6.0.3 - SQLi in WP_Date_Query
| [!] Title: WP < 6.0.3 - Stored XSS via RSS Widget
| [!] Title: WP < 6.0.3 - Data Exposure via REST Terms/Tags Endpoint
| [!] Title: WP < 6.0.3 - Multiple Stored XSS via Gutenberg
| [!] Title: WP <= 6.2 - Unauthenticated Blind SSRF via DNS Rebinding
| [!] Title: WP < 6.2.1 - Directory Traversal via Translation Files
| [!] Title: WP < 6.2.1 - Thumbnail Image Update via CSRF
| [!] Title: WP < 6.2.1 - Contributor+ Stored XSS via Open Embed Auto Discovery
| [!] Title: WP < 6.2.2 - Shortcode Execution in User Generated Data
| [!] Title: WP < 6.2.1 - Contributor+ Content Injection
| [!] Title: WordPress 4.7-5.7 - Authenticated Password Protected Pages Exposure
| [!] Title: WordPress 3.7 to 5.7.1 - Object Injection in PHPMailer
| [!] Title: WordPress 5.4 to 5.8 - Lodash Library Update
| [!] Title: WordPress 5.4 to 5.8 - Authenticated XSS in Block Editor
| [!] Title: WordPress 5.4 to 5.8 - Data Exposure via REST API
| [!] Title: WordPress < 5.8.2 - Expired DST Root CA X3 Certificate
| [!] Title: WordPress < 5.8 - Plugin Confusion
| [!] Title: WordPress < 5.8.3 - SQL Injection via WP_Query
| [!] Title: WordPress < 5.8.3 - Author+ Stored XSS via Post Slugs
| [!] Title: WordPress 4.1-5.8.2 - SQL Injection via WP_Meta_Query
| [!] Title: WordPress < 5.8.3 - Super Admin Object Injection in Multisites
| [!] Title: WordPress < 5.9.2 - Prototype Pollution in jQuery
| [!] Title: WP < 6.0.2 - Reflected Cross-Site Scripting
| [!] Title: WP < 6.0.2 - Authenticated Stored Cross-Site Scripting
| [!] Title: WP < 6.0.2 - SQLi via Link API
| [!] Title: WP < 6.0.3 - Stored XSS via wp-mail.php
| [!] Title: WP < 6.0.3 - Open Redirect via wp_nonce_ays
| [!] Title: WP < 6.0.3 - Email Address Disclosure via wp-mail.php
| [!] Title: WP < 6.0.3 - Reflected XSS via SQLi in Media Library
| [!] Title: WP < 6.0.3 - CSRF in wp-trackback.php
| [!] Title: WP < 6.0.3 - Stored XSS via the Customizer
| [!] Title: WP < 6.0.3 - Stored XSS via Comment Editing
| [!] Title: WP < 6.0.3 - Content from Multipart Emails Leaked
| [!] Title: WP < 6.0.3 - SQLi in WP_Date_Query
| [!] Title: WP < 6.0.3 - Stored XSS via RSS Widget
| [!] Title: WP < 6.0.3 - Data Exposure via REST Terms/Tags Endpoint
| [!] Title: WP < 6.0.3 - Multiple Stored XSS via Gutenberg
| [!] Title: WP <= 6.2 - Unauthenticated Blind SSRF via DNS Rebinding
| [!] Title: WP < 6.2.1 - Directory Traversal via Translation Files
| [!] Title: WP < 6.2.1 - Thumbnail Image Update via CSRF
| [!] Title: WP < 6.2.1 - Contributor+ Stored XSS via Open Embed Auto Discovery
| [!] Title: WP < 6.2.2 - Shortcode Execution in User Generated Data
| [!] Title: WP < 6.2.1 - Contributor+ Content Injection