Répertoire de sécurité WordPress
Vulnérabilités du cœur WordPress, page 15
Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 15 de l’annuaire.
WordPress Core
Failles et CVE du cœur WordPress
WordPress Core & WordPress MU < 2.8.1 – Full Path Disclosure
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.
*-2.8
2.8.1
08/09/2009
WordPress Core & WordPress MU < 2.8.1 – Full Path Disclosure
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.
*-2.8
2.8.1
08/09/2009
WordPress Core < 2.8.4 – Forced Password Reset
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a…
*-2.8.3
2.8.4
12/08/2009
WordPress Core < 2.8.3 – Authorization Bypass
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
*-2.8.2
2.8.3
03/08/2009
WordPress Core < 2.8.3 – Missing Authorization
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7)…
*-2.8.2
2.8.3
03/08/2009
WordPress Core <= 2.8.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.
*-2.8.1
2.8.2
20/07/2009
WordPress Core & WordPress MU < 2.8.1 – Username Enumeration
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this…
*-2.8
2.8.1
09/07/2009
WordPress Core & WordPress MU < 2.8.1 – Username Enumeration
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this…
*-2.8
2.8.1
09/07/2009
WordPress Core <= 2.8 – Sensitive Information Disclosure
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or…
*-2.8
2.8.1
09/07/2009
WordPress Core <= 2.8 – Sensitive Information Disclosure
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or…
*-2.8
2.8.1
09/07/2009
WordPress Core & WordPress MU < 2.8.1 – Username Enumeration
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes…
*-2.8
2.8.1
09/07/2009
WordPress Core & WordPress MU < 2.8.1 – Username Enumeration
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes…
*-2.8
2.8.1
09/07/2009
WordPress Core < 2.8 – Sensitive Information Disclosure
WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.
*-2.7.1
2.8
11/06/2009
WordPress MU < 2.7 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
[*, 2.7)
2.7
10/03/2009
WordPress Core < 2.6.5 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
*-2.6.4
2.6.5
25/12/2008
WordPress Core < 2.8.1 – Open Redirect
Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.
[*, 2.8.1)
2.8.1
22/12/2008
WordPress Core < 2.7 – Denial of Service
wp-admin/upgrade.php in WordPress up to and including 2.6.1, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request if WordPress is not yet setup by creating an empty…
*-2.6.1
2.7
22/12/2008
WordPress Core < 2.6.2 – Cryptographic Weakness
The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these functions for security-relevant functionality, as demonstrated by the password-reset…
*-2.6.1
2.6.2
08/09/2008
WordPress Core < 2.6.2 – Arbitrary User Password Reset
WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers…
*-2.6.1
2.6.2
08/09/2008
WordPress MU < 2.6 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address parameters.
[*, 2.6)
2.6
01/09/2008
Comprendre les données
Comment utiliser cet annuaire de vulnérabilités ?
Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.
Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.