Base locale WP Commander
Vulnérabilités WordPress connues
Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.
43 038 résultats
Page 3567 sur 3587
is-human <= 1.4.2 – Unauthenticated Remote Code Execution
The is-human plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.2 via the /plugins/is-human/engine.php file. This is due to the plugin accepting user-supplied input passed to eval(). This makes it…
*-1.4.2
Non indiqué
16/05/2011
WordPress Core < 3.1.2 – Incorrect Authorization for Contributor-level users
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
*-3.1.1
3.1.2
26/04/2011
Sermon Browser < 0.43.6 – SQL Injection
The Sermon Browser plugin for WordPress is vulnerable to SQL Injection via the ‘sermon_id’ parameter in versions before 0.43.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
[*, 0.43.6)
0.43.6
26/04/2011
Sermon Browser < 0.43.6 – Cross-Site Scripting
The Sermon Browser plugin for WordPress is vulnerable to Cross-Site Scripting via the 'file_name' parameter in versions before 0.43.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts…
[*, 0.43.6)
0.43.6
26/04/2011
WordPress Core < 3.0.6 – Incorrect Authorization Checks
wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.
[*, 3.0.6)
3.0.6
26/04/2011
SocialGrid <= 2.4 – Cross-Site Scripting
The SocialGrid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘default_services’ parameter in versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-2.4
Non indiqué
19/04/2011
WordPress Core < 3.1.1 – Denial of Service
The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE library, which allows remote attackers to cause a denial of service (crash) via a comment with a crafted…
[*, 3.1.1)
3.1.1
05/04/2011
WordPress Core <= 3.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
*-3.1
3.1.1
05/04/2011
WP Custom Pages <= 0.5.0.1 – Path Traversal
Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter.
*-0.5.0.1
Non indiqué
03/04/2011
BackWPup <= 1.7.1 – Remote File Inclusion
PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter.
*-1.7.1
1.7.2
28/03/2011
WP-reCAPTCHA <= 2.9.8.2 – Multiple Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration page in the Recaptcha (aka WP-reCAPTCHA) plugin 2.9.8.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that disable the CAPTCHA requirement or insert cross-site…
*-2.9.8.2
3.0
17/03/2011
WP Related Posts <= 1.0 – Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration screen in wp-relatedposts.php in the WP Related Posts plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences…
[*, 1.1)
1.1
17/03/2011