Répertoire de sécurité WordPress
Vulnérabilités du cœur WordPress, page 15
Consultez 389 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 15 de l’annuaire.
WordPress Core
Failles et CVE du cœur WordPress
WordPress Core < 3.0.2 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.
[*, 3.0.2)
3.0.2
30/11/2010
WordPress Core <= 3.0.1 – SQL Injection
SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.
*-3.0.1
3.0.2
30/11/2010
WordPress Core < 3.0.2 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH…
[*, 3.0.2)
3.0.2
30/11/2010
WordPress Core < 3.0.2 – Spam Protection Bypass
wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.
[*, 3.0.2)
3.0.2
30/11/2010
WordPress Core < 3.0.1 – Missing Authorization
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action…
[*, 3.0.1)
3.0.1
29/07/2010
WordPress Core < 2.9.2 – Authorization Bypass
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.
[*, 2.9.2)
2.9.2
15/02/2010
WordPress Core <= 2.8.5 – Arbitrary File Upload
Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by…
*-2.8.5
2.8.6
12/12/2009
WordPress Core <= 2.8.5 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).
*-2.8.5
2.8.6
12/12/2009
WordPress Core <= 2.8.4 – Denial of Service
Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated…
*-2.8.4
2.8.5
20/10/2009
WordPress Core & WordPress MU < 2.8.1 – Full Path Disclosure
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.
*-2.8
2.8.1
08/09/2009
WordPress Core & WordPress MU < 2.8.1 – Full Path Disclosure
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.
*-2.8
2.8.1
08/09/2009
WordPress Core < 2.8.4 – Forced Password Reset
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a…
*-2.8.3
2.8.4
12/08/2009
WordPress Core < 2.8.3 – Authorization Bypass
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
*-2.8.2
2.8.3
03/08/2009
WordPress Core < 2.8.3 – Missing Authorization
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7)…
*-2.8.2
2.8.3
03/08/2009
WordPress Core <= 2.8.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.
*-2.8.1
2.8.2
20/07/2009
WordPress Core & WordPress MU < 2.8.1 – Username Enumeration
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this…
*-2.8
2.8.1
09/07/2009
WordPress Core & WordPress MU < 2.8.1 – Username Enumeration
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this…
*-2.8
2.8.1
09/07/2009
WordPress Core <= 2.8 – Sensitive Information Disclosure
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or…
*-2.8
2.8.1
09/07/2009
WordPress Core <= 2.8 – Sensitive Information Disclosure
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or…
*-2.8
2.8.1
09/07/2009
WordPress Core & WordPress MU < 2.8.1 – Username Enumeration
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes…
*-2.8
2.8.1
09/07/2009
Comprendre les données
Comment utiliser cet annuaire de vulnérabilités ?
Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.
Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.