Répertoire de sécurité WordPress
Vulnérabilités du cœur WordPress, page 14
Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 14 de l’annuaire.
WordPress Core
Failles et CVE du cœur WordPress
WordPress Core < 3.1.3 – Security Hardening
Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hardening."
*-3.1.2
3.1.3
25/05/2011
WordPress Core < 3.1.3 – Media Related Security Issue
Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."
*-3.1.2
3.2
25/05/2011
WordPress Core < 3.1.2 – Incorrect Authorization for Contributor-level users
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
*-3.1.1
3.1.2
26/04/2011
WordPress Core < 3.0.6 – Incorrect Authorization Checks
wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.
[*, 3.0.6)
3.0.6
26/04/2011
WordPress Core < 3.1.1 – Denial of Service
The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE library, which allows remote attackers to cause a denial of service (crash) via a comment with a crafted…
[*, 3.1.1)
3.1.1
05/04/2011
WordPress Core <= 3.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
*-3.1
3.1.1
05/04/2011
WordPress Core < 3.0.5 – Improper Authorization to Information Disclosure
wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.
*-3.0.4
3.0.5
07/02/2011
WordPress Core 2.9.2 and 3.0.4 – Sensitive Information Disclosure
WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.
2.9.2, 3.0.4
3.0, 3.0.5
28/01/2011
WordPress Core < 3.0.2 – Missing Authorization
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
[*, 3.0.2)
3.0.2
30/12/2010
WordPress Core <= 3.0.3 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute…
*-3.0.3
3.0.4
29/12/2010
WordPress Core < 3.0.3 – Access Control Bypass
The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor…
*-3.0.2
3.0.3
08/12/2010
WordPress Core < 3.0.2 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.
[*, 3.0.2)
3.0.2
30/11/2010
WordPress Core <= 3.0.1 – SQL Injection
SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.
*-3.0.1
3.0.2
30/11/2010
WordPress Core < 3.0.2 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH…
[*, 3.0.2)
3.0.2
30/11/2010
WordPress Core < 3.0.2 – Spam Protection Bypass
wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.
[*, 3.0.2)
3.0.2
30/11/2010
WordPress Core < 3.0.1 – Missing Authorization
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action…
[*, 3.0.1)
3.0.1
29/07/2010
WordPress Core < 2.9.2 – Authorization Bypass
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.
[*, 2.9.2)
2.9.2
15/02/2010
WordPress Core <= 2.8.5 – Arbitrary File Upload
Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by…
*-2.8.5
2.8.6
12/12/2009
WordPress Core <= 2.8.5 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).
*-2.8.5
2.8.6
12/12/2009
WordPress Core <= 2.8.4 – Denial of Service
Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated…
*-2.8.4
2.8.5
20/10/2009
Comprendre les données
Comment utiliser cet annuaire de vulnérabilités ?
Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.
Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.