Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 17

Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 17 de l’annuaire.

380Vulnérabilités
17Critiques
378Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

CVE-2007-4154 Élevée · 8,8
WordPress

WordPress Core <= 2.2.1 – SQL Injection

SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the page_options parameter to (1) options-general.php, (2) options-writing.php, (3) options-reading.php, (4) options-discussion.php, (5) options-privacy.php, (6) options-permalink.php, (7) options-misc.php, and possibly…

Versions affectées

*-2.0.10, 2.2-2.2.1

Correctif

2.0.11, 2.2.2

Publication

05/08/2007

CVE-2007-3543 Élevée · 8,8
WordPress

WordPress Core <= 2.2 – Arbitrary File Upload

Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field;…

Versions affectées

*-2.2

Correctif

2.2.1

Publication

05/08/2007

CVE-2007-4139 Moyenne · 6,4
WordPress

WordPress Core <= 2.2.1 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the Temporary Uploads editing functionality (wp-admin/includes/upload.php) in WordPress 2.2.1, allows remote attackers to inject arbitrary web script or HTML via the style parameter to wp-admin/upload.php.

Versions affectées

*-2.0.10, 2.2-2.2.1

Correctif

2.0.11, 2.2.2

Publication

05/08/2007

CVE-2007-4893 Moyenne · 6,4
WordPress

WordPress Core <= 2.2.2 – Cross-Site Scripting

wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with…

Versions affectées

*-2.2.2

Correctif

2.2.3

Publication

05/08/2007

CVE-2007-4893 Moyenne · 6,4
WordPress MU

WordPress Core <= 2.2.2 – Cross-Site Scripting

wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with…

Versions affectées

[*, 1.2.5a)

Correctif

1.2.5a

Publication

05/08/2007

CVE-2007-3544 Élevée · 8,8
WordPress

WordPress Core <= 2.2.1 – Arbitrary File Upload

Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and…

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

05/08/2007

CVE-2007-3544 Élevée · 8,8
WordPress MU

WordPress Core <= 2.2.1 – Arbitrary File Upload

Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and…

Versions affectées

*-1.2.3

Correctif

1.2.4

Publication

05/08/2007

CVE-2007-2627 Moyenne · 6,1
WordPress

WordPress Core <= 2.2 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.

Versions affectées

*-2.2

Correctif

2.2.1

Publication

21/06/2007

CVE-2007-3140 Élevée · 8,8
WordPress

WordPress Core <= 2.2 – SQL Injection

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.

Versions affectées

*-2.2

Correctif

2.2.1

Publication

21/06/2007

CVE-2007-1622 Moyenne · 6,1
WordPress

WordPress Core <= 2.1.2 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the…

Versions affectées

*-2.0.9, 2.1-2.1.1

Correctif

2.0.10, 2.1.2

Publication

03/04/2007

CVE-2007-1897 Élevée · 8,8
WordPress

WordPress Core < 2.1.3 – SQL Injection

SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.

Versions affectées

[*, 2.1.3)

Correctif

2.1.3

Publication

03/04/2007

CVE-2007-1893 Moyenne · 4,3
WordPress

WordPress Core < 2.1.3 – Authorization Bypass

xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."

Versions affectées

*-2.1.2

Correctif

2.1.3

Publication

03/04/2007

CVE-2007-1277 Critique · 9,8
WordPress

WordPress Core 2.2.1 – Backdoor

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to…

Versions affectées

2.2.1

Correctif

2.2.2

Publication

03/03/2007

CVE-2007-1244 Moyenne · 6,4
WordPress

WordPress Core <= 2.1.1 – Cross-Site Scripting

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform…

Versions affectées

*-2.1.1

Correctif

2.1.2

Publication

02/03/2007

CVE-2007-1230 Moyenne · 6,4
WordPress

WordPress Core <= 2.1.1 – Cross-Site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

Versions affectées

*-2.1.1

Correctif

2.1.2

Publication

02/03/2007

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités