Répertoire de sécurité WordPress
Vulnérabilités du cœur WordPress, page 13
Consultez 389 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 13 de l’annuaire.
WordPress Core
Failles et CVE du cœur WordPress
WordPress Core <= 3.5.1 – Content-Spoofing Attacks
moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers…
*-3.5.1
3.5.2
21/06/2013
WordPress Core < 3.5.2 – XXE Injection
WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
*-3.5.1
3.5.2
21/06/2013
WordPress Core < 3.5.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
*-3.5
3.5.1
24/01/2013
WordPress Core < 3.5.1 – Server-Side Request Forgery
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.
*-3.5
3.5.1
24/01/2013
WordPress Core < 3.5.1 – Stored Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
[*, 3.5.1)
3.5.1
24/01/2013
WordPress Core < 4.0 – Missing Session Cookie Expiration
WordPress Core before 4.0 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay…
[*, 4.0)
4.0
27/12/2012
SWFUpload <= 2.2.0.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter,…
[*, 3.3.2)
3.3.2
09/11/2012
WordPress Core < 3.4.2 – Cross-Site Scripting
The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS)…
*-3.4.1
3.4.2
06/09/2012
WordPress Core < 3.4.2 – Missing Authorization Checks
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by…
*-3.4.1
3.4.2
06/09/2012
WordPress Core < 3.4.2 – Missing Authorization Checks on create_post
The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom…
[*, 3.4.2)
3.4.2
06/09/2012
WordPress Core < 3.4.1 – Information Disclosure
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.
*-3.4
3.4.1
27/06/2012
WordPress Core <= 3.3.2 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.
[*, 3.3.3)
3.3.3
27/06/2012
WordPress Core < 3.4.1 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
*-3.4
3.4.1
27/06/2012
WordPress Core <= 3.3.2 – Sensitive Information Disclosure
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.
[*, 3.3.3)
3.3.3
27/06/2012
WordPress Core <= 3.3.2 – Sensitive Information Disclosure
wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.
[*, 3.3.3)
3.3.3
27/06/2012
WordPress Core – Informational < 6.8 – Weak Hashing Algorithm
Versions of WordPress core older than version 6.8 use a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this…
[*, 6.8)
6.8
20/06/2012
WordPress Core <= 3.5.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the…
*-3.5.1
3.5.2
21/04/2012
WordPress Core <= 3.3.1 – Cross-Site Scripting
wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
*-3.3.1
3.3.2
21/04/2012
WordPress Core < 3.3.2 – Authorization Bypass
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.
*-3.3.1
3.3.2
20/04/2012
WordPress Core < 3.3.2 – Cross-Site Scripting
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
*-3.3.1
3.3.2
20/04/2012
Comprendre les données
Comment utiliser cet annuaire de vulnérabilités ?
Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.
Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.