Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 10

Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 10 de l’annuaire.

380Vulnérabilités
17Critiques
378Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

CVE-2016-2221 Moyenne · 5,4
WordPress

WordPress Core < 4.4.2 – Open Redirect via wp_validate_redirect

Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated…

Versions affectées

[*, 3.7), 3.7-3.7.12, 3.8-3.8.12, 3.9-3.9.10, 4.0-4.0.9, 4.1-4.1.9, 4.2-4.2.6, 4.3-4.3.2, 4.4-4.4.1

Correctif

3.7.13, 3.8.13, 3.9.11, 4.0.10, 4.1.10, 4.2.7, 4.3.3, 4.4.2

Publication

02/02/2016

CVE-2016-2222 Moyenne · 6,4
WordPress

WordPress Core < 4.4.2 – Server-Side Request Forgery

The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.

Versions affectées

[*, 3.7), 3.7-3.7.12, 3.8-3.8.12, 3.9-3.9.10, 4.0-4.0.9, 4.1-4.1.9, 4.2-4.2.6, 4.3-4.3.2, 4.4-4.4.1

Correctif

3.7.13, 3.8.13, 3.9.11, 4.0.10, 4.1.10, 4.2.7, 4.3.3, 4.4.2

Publication

02/02/2016

CVE-2016-1564 Moyenne · 5,5
WordPress

WordPress Core < 4.4.1 – Cross-Site Scripting via Theme Names

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.

Versions affectées

[*, 3.7), 3.7-3.7.11, 3.8-3.8.11, 3.9-3.9.9, 4.0-4.0.8, 4.1-4.1.8, 4.2-4.2.5, 4.3-4.3.1, 4.4

Correctif

3.7.12, 3.8.12, 3.9.10, 4.0.9, 4.1.9, 4.2.6, 4.3.2, 4.4.1

Publication

16/01/2016

CVE-2015-5714 Moyenne · 6,4
WordPress

WordPress Core < 4.3.1 – Cross-Site Scripting via Shortcodes

Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.

Versions affectées

[*, 3.7), 3.7-3.7.10, 3.8-3.8.10, 3.9-3.9.8, 4.0-4.0.7, 4.1-4.1.7, 4.2-4.2.4, 4.3

Correctif

3.7.11, 3.8.11, 3.9.9, 4.0.8, 4.1.8, 4.2.5, 4.3.1

Publication

15/09/2015

CVE-2015-5715 Moyenne · 5,4
WordPress

WordPress Core < 4.3.1 – Authorization Bypass to Information Disclosure

The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.

Versions affectées

[*, 3.7), 3.7-3.7.10, 3.8-3.8.10, 3.9-3.9.8, 4.0-4.0.7, 4.1-4.1.7, 4.2-4.2.4, 4.3

Correctif

3.7.11, 3.8.11, 3.9.9, 4.0.8, 4.1.8, 4.2.5, 4.3.1

Publication

15/09/2015

CVE-2015-7989 Moyenne · 6,4
WordPress

WordPress Core < 4.3.1 – Authenticated Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.

Versions affectées

[*, 3.7), 3.7-3.7.10, 3.8-3.8.10, 3.9-3.9.8, 4.0-4.0.7, 4.1-4.1.7, 4.2-4.2.4, 4.3

Correctif

3.7.11, 3.8.11, 3.9.9, 4.0.8, 4.1.8, 4.2.5, 4.3.1

Publication

15/09/2015

CVE-2015-2213 Élevée · 8,8
WordPress

WordPress Core < 4.2.4 – SQL Injection

SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.

Versions affectées

[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3

Correctif

3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4

Publication

04/08/2015

CVE-2015-5734 Moyenne · 6,1
WordPress

WordPress Core < 4.2.4 – Cross-Site Scripting in Theme Preview

Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.

Versions affectées

[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3

Correctif

3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4

Publication

04/08/2015

CVE-2015-5732 Moyenne · 5,5
WordPress

WordPress Core < 4.2.4 – Cross-Site Scripting via Widget Title

Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.

Versions affectées

[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3

Correctif

3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4

Publication

04/08/2015

CVE-2015-5730 Moyenne · 5,3
WordPress

WordPress Core < 4.2.4 – Timing Side-Channel Attack

The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.

Versions affectées

[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3

Correctif

3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4

Publication

04/08/2015

CVE-2015-5731 Critique · 9,6
WordPress

WordPress Core < 4.2.4 – Cross-Site Request Forgery to Post Lockage

Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock…

Versions affectées

[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3

Correctif

3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4

Publication

04/08/2015

CVE-2015-5733 Moyenne · 5,4
WordPress

WordPress Core < 4.2.4 – Stored Cross-Site Scripting via accessibility-helper Title

Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.

Versions affectées

[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3

Correctif

3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4

Publication

04/08/2015

CVE-2015-5623 Moyenne · 6,5
WordPress

WordPress Core < 4.2.3 – Authorization Bypass

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

Versions affectées

[*, 3.7), 3.7-3.7.8, 3.8-3.8.8, 3.9-3.9.6, 4.0-4.0.5, 4.1-4.1.5, 4.2-4.2.2

Correctif

3.7.9, 3.8.9, 3.9.7, 4.0.6, 4.1.6, 4.2.3

Publication

23/07/2015

CVE-2015-5622 Moyenne · 6,4
WordPress

WordPress Core < 4.2.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php…

Versions affectées

[*, 3.7), 3.7-3.7.8, 3.8-3.8.8, 3.9-3.9.6, 4.0-4.0.5, 4.1-4.1.5, 4.2-4.2.2

Correctif

3.7.9, 3.8.9, 3.9.7, 4.0.6, 4.1.6, 4.2.3

Publication

23/07/2015

CVE-2015-8834 Élevée · 7,2
WordPress

WordPress Core < 4.2.2 – Cross-Site Scripting via Comments

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE:…

Versions affectées

[*, 3.7), 3.7-3.7.7, 3.8-3.8.7, 3.9-3.9.5, 4.0-4.0.4, 4.1-4.1.4, 4.2-4.2.1

Correctif

3.7.8, 3.8.8, 3.9.6, 4.0.5, 4.1.5, 4.2.2

Publication

07/05/2015

CVE-2015-3438 Élevée · 7,2
WordPress

WordPress Core < 4.1.2 – Cross-Site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches…

Versions affectées

[*, 3.7), 3.7-3.7.5, 3.8-3.8.5, 3.9-3.9.3, 4.0-4.0.1, 4.1-4.1.1

Correctif

3.7.6, 3.8.6, 3.9.4, 4.0.2, 4.1.2

Publication

21/04/2015

CVE-2015-3439 Moyenne · 5,4
WordPress

WordPress Core < 4.1.2 – Cross-Site Scripting via Ephox in Plupload

Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target…

Versions affectées

[*, 3.7), 3.7-3.7.5, 3.8-3.8.5, 3.9-3.9.3, 4.0-4.0.1, 4.1-4.1.1

Correctif

3.7.6, 3.8.6, 3.9.4, 4.0.2, 4.1.2

Publication

20/04/2015

CVE-2015-3429 Moyenne · 6,4
WordPress

Twenty Fifteen Theme <= 1.1 & WordPress Core < 4.2.2 – Cross-Site Scripting via example.html

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

Versions affectées

[*, 3.7), 3.7-3.7.7, 3.8-3.8.7, 3.9-3.9.5, 4.0-4.0.4, 4.1-4.1.4, 4.2-4.2.1

Correctif

3.7.8, 3.8.8, 3.9.6, 4.0.5, 4.1.5, 4.2.2

Publication

08/04/2015

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités