Répertoire de sécurité WordPress
Vulnérabilités du cœur WordPress, page 16
Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 16 de l’annuaire.
WordPress Core
Failles et CVE du cœur WordPress
WordPress Core < 2.6.1 – Cryptographic Weakness
The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.
*-2.6
2.6.1
15/08/2008
WordPress Core < 2.6 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
[*, 2.6)
2.6
15/07/2008
WordPress Core <= 2.5.1 – Arbitrary File Upload
Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary PHP files via the Upload section in the Write Tabs area of the dashboard.
*-2.5.1
2.5.2
25/04/2008
WordPress Core <= 2.5 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
*-2.5
2.5.1
25/04/2008
WordPress Core <= 2.3.3 – Directory Traversal
Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details…
*-2.3.3, 2.5
2.5.1
25/04/2008
WordPress Core < 2.5.1 – Authentication Bypass
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as…
*-2.5
2.5.1
25/04/2008
WordPress Core <= 2.3.2 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action…
*-2.3.2
2.3.3
05/02/2008
WordPress Core 1.5 – 2.3.1 – Authorization Bypass
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from…
1.5-2.3.1
2.3.2
29/12/2007
WordPress Core < 2.5 – Full Path Disclosure
WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.
*-2.4
2.5
16/12/2007
WordPress Core <= 2.3 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.
*-2.3
2.3.1
26/10/2007
WordPress Core < 2.0.4 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 allows remote attackers to inject arbitrary web script or HTML via the user_login parameter.
*-2.0.3
2.0.4
21/09/2007
WordPress Core < 2.2.3 – Restriction Bypass
wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.
*-2.2.2
2.2.3
08/09/2007
WordPress Core < 2.2.3 & WordPress MU < 1.2.5a – SQL Injection
Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters…
[*, 2.2.3)
2.2.3
08/09/2007
WordPress Core < 2.2.3 & WordPress MU < 1.2.5a – SQL Injection
Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters…
[*, 1.2.5)
1.2.5
08/09/2007
WordPress Core < 2.3.3 – Improper Authorization Checks
The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors.
*-2.3.2
2.3.3
08/09/2007
WordPress Core < 2.3.3 & WordPress MU < 1.3.2 – Remote Code Execution
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP…
*-2.3.2
2.3.3
08/09/2007
WordPress Core < 2.3.3 & WordPress MU < 1.3.2 – Remote Code Execution
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP…
*-1.3.1
1.3.2
08/09/2007
WordPress Core < 2.3.2 – SQL Injection
SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that…
*-2.3.1
2.3.2
08/09/2007
WordPress MU <= 1.0 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field).
*-1.0
1.1.1
22/08/2007
WordPress Core < 2.2.2 – Open Redirect
WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2)…
*-2.2.1
2.2.2
08/08/2007
Comprendre les données
Comment utiliser cet annuaire de vulnérabilités ?
Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.
Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.