Répertoire de sécurité WordPress
Vulnérabilités du cœur WordPress, page 10
Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 10 de l’annuaire.
WordPress Core
Failles et CVE du cœur WordPress
WordPress Core < 4.4.2 – Open Redirect via wp_validate_redirect
Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated…
[*, 3.7), 3.7-3.7.12, 3.8-3.8.12, 3.9-3.9.10, 4.0-4.0.9, 4.1-4.1.9, 4.2-4.2.6, 4.3-4.3.2, 4.4-4.4.1
3.7.13, 3.8.13, 3.9.11, 4.0.10, 4.1.10, 4.2.7, 4.3.3, 4.4.2
02/02/2016
WordPress Core < 4.4.2 – Server-Side Request Forgery
The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.
[*, 3.7), 3.7-3.7.12, 3.8-3.8.12, 3.9-3.9.10, 4.0-4.0.9, 4.1-4.1.9, 4.2-4.2.6, 4.3-4.3.2, 4.4-4.4.1
3.7.13, 3.8.13, 3.9.11, 4.0.10, 4.1.10, 4.2.7, 4.3.3, 4.4.2
02/02/2016
WordPress Core < 4.4.1 – Cross-Site Scripting via Theme Names
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.
[*, 3.7), 3.7-3.7.11, 3.8-3.8.11, 3.9-3.9.9, 4.0-4.0.8, 4.1-4.1.8, 4.2-4.2.5, 4.3-4.3.1, 4.4
3.7.12, 3.8.12, 3.9.10, 4.0.9, 4.1.9, 4.2.6, 4.3.2, 4.4.1
16/01/2016
WordPress Core < 4.3.1 – Cross-Site Scripting via Shortcodes
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.
[*, 3.7), 3.7-3.7.10, 3.8-3.8.10, 3.9-3.9.8, 4.0-4.0.7, 4.1-4.1.7, 4.2-4.2.4, 4.3
3.7.11, 3.8.11, 3.9.9, 4.0.8, 4.1.8, 4.2.5, 4.3.1
15/09/2015
WordPress Core < 4.3.1 – Authorization Bypass to Information Disclosure
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.
[*, 3.7), 3.7-3.7.10, 3.8-3.8.10, 3.9-3.9.8, 4.0-4.0.7, 4.1-4.1.7, 4.2-4.2.4, 4.3
3.7.11, 3.8.11, 3.9.9, 4.0.8, 4.1.8, 4.2.5, 4.3.1
15/09/2015
WordPress Core < 4.3.1 – Authenticated Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.
[*, 3.7), 3.7-3.7.10, 3.8-3.8.10, 3.9-3.9.8, 4.0-4.0.7, 4.1-4.1.7, 4.2-4.2.4, 4.3
3.7.11, 3.8.11, 3.9.9, 4.0.8, 4.1.8, 4.2.5, 4.3.1
15/09/2015
WordPress Core < 4.2.4 – SQL Injection
SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.
[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3
3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4
04/08/2015
WordPress Core < 4.2.4 – Cross-Site Scripting in Theme Preview
Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a crafted string.
[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3
3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4
04/08/2015
WordPress Core < 4.2.4 – Cross-Site Scripting via Widget Title
Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.
[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3
3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4
04/08/2015
WordPress Core < 4.2.4 – Timing Side-Channel Attack
The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.
[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3
3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4
04/08/2015
WordPress Core < 4.2.4 – Cross-Site Request Forgery to Post Lockage
Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock…
[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3
3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4
04/08/2015
WordPress Core < 4.2.4 – Stored Cross-Site Scripting via accessibility-helper Title
Cross-site scripting (XSS) vulnerability in the refreshAdvancedAccessibilityOfItem function in wp-admin/js/nav-menu.js in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via an accessibility-helper title.
[*, 3.7), 3.7-3.7.9, 3.8-3.8.9, 3.9-3.9.7, 4.0-4.0.6, 4.1-4.1.6, 4.2-4.2.3
3.7.10, 3.8.10, 3.9.8, 4.0.7, 4.1.7, 4.2.4
04/08/2015
WordPress Core < 4.2.3 – Authorization Bypass
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.
[*, 3.7), 3.7-3.7.8, 3.8-3.8.8, 3.9-3.9.6, 4.0-4.0.5, 4.1-4.1.5, 4.2-4.2.2
3.7.9, 3.8.9, 3.9.7, 4.0.6, 4.1.6, 4.2.3
23/07/2015
WordPress Core < 4.2.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php…
[*, 3.7), 3.7-3.7.8, 3.8-3.8.8, 3.9-3.9.6, 4.0-4.0.5, 4.1-4.1.5, 4.2-4.2.2
3.7.9, 3.8.9, 3.9.7, 4.0.6, 4.1.6, 4.2.3
23/07/2015
WordPress Core < 4.2.2 – Cross-Site Scripting via Comments
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NOTE:…
[*, 3.7), 3.7-3.7.7, 3.8-3.8.7, 3.9-3.9.5, 4.0-4.0.4, 4.1-4.1.4, 4.2-4.2.1
3.7.8, 3.8.8, 3.9.6, 4.0.5, 4.1.5, 4.2.2
07/05/2015
WordPress Core < 4.2.1 – Cross-Site Scripting via Comments
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.
4.0-4.0.3, 4.1-4.1.3, 4.2
4.0.4, 4.1.4, 4.2.1
27/04/2015
WordPress Core < 4.1.2 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches…
[*, 3.7), 3.7-3.7.5, 3.8-3.8.5, 3.9-3.9.3, 4.0-4.0.1, 4.1-4.1.1
3.7.6, 3.8.6, 3.9.4, 4.0.2, 4.1.2
21/04/2015
WordPress Core < 4.1.2 – Cross-Site Scripting via Ephox in Plupload
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target…
[*, 3.7), 3.7-3.7.5, 3.8-3.8.5, 3.9-3.9.3, 4.0-4.0.1, 4.1-4.1.1
3.7.6, 3.8.6, 3.9.4, 4.0.2, 4.1.2
20/04/2015
Twenty Fifteen Theme <= 1.1 & WordPress Core < 4.2.2 – Cross-Site Scripting via example.html
Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.
[*, 3.7), 3.7-3.7.7, 3.8-3.8.7, 3.9-3.9.5, 4.0-4.0.4, 4.1-4.1.4, 4.2-4.2.1
3.7.8, 3.8.8, 3.9.6, 4.0.5, 4.1.5, 4.2.2
08/04/2015
WordPress Core < 4.4 – Brute Force Password Recovery Tokens
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
[*, 4.4)
4.4
12/02/2015
Comprendre les données
Comment utiliser cet annuaire de vulnérabilités ?
Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.
Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.