Répertoire de sécurité WordPress
Vulnérabilités du cœur WordPress, page 13
Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 13 de l’annuaire.
WordPress Core
Failles et CVE du cœur WordPress
WordPress Core < 3.4.2 – Missing Authorization Checks on create_post
The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom…
[*, 3.4.2)
3.4.2
06/09/2012
WordPress Core < 3.4.1 – Information Disclosure
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.
*-3.4
3.4.1
27/06/2012
WordPress Core <= 3.3.2 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.
[*, 3.3.3)
3.3.3
27/06/2012
WordPress Core < 3.4.1 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
*-3.4
3.4.1
27/06/2012
WordPress Core <= 3.3.2 – Sensitive Information Disclosure
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.
[*, 3.3.3)
3.3.3
27/06/2012
WordPress Core <= 3.3.2 – Sensitive Information Disclosure
wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.
[*, 3.3.3)
3.3.3
27/06/2012
WordPress Core – Informational < 6.8 – Weak Hashing Algorithm
Versions of WordPress core older than version 6.8 use a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this…
[*, 6.8)
6.8
20/06/2012
WordPress Core <= 3.5.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the…
*-3.5.1
3.5.2
21/04/2012
WordPress Core <= 3.3.1 – Cross-Site Scripting
wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
*-3.3.1
3.3.2
21/04/2012
WordPress Core < 3.3.2 – Authorization Bypass
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.
*-3.3.1
3.3.2
20/04/2012
WordPress Core < 3.3.2 – Cross-Site Scripting
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
*-3.3.1
3.3.2
20/04/2012
WordPress Core <= 3.3.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter,…
*-3.3.1
3.3.2
20/04/2012
WordPress Core < 3.3.2 – Cross-Site Scripting
wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
*-3.3.1
3.3.2
20/04/2012
WordPress Core <= 3.3.1 – Same Origin Policy Bypass
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via…
[*, 3.3.2)
3.3.2
20/04/2012
WordPress Core <= 3.3 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly…
*-3.3
3.3.1
03/01/2012
WordPress Core < 3.1.3 – Clickjacking
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking…
*-3.1.2
3.1.3
25/05/2011
WordPress Core < 3.1.3 – Sensitive Information Disclosure
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php.
*-3.1.2
3.1.3
25/05/2011
WordPress Core <= 3.1.2 – SQL Injection
wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.
*-3.1.2
3.1.3
25/05/2011
WordPress Core <= 3.1.2 – Arbitrary File Upload
The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.
*-3.1.2
3.1.3
25/05/2011
WordPress Core < 3.1.3 – Username Enumeration
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.
*-3.1.2
3.1.3
25/05/2011
Comprendre les données
Comment utiliser cet annuaire de vulnérabilités ?
Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.
Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.