Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 2

Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 2 de l’annuaire.

380Vulnérabilités
17Critiques
378Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

CVE-2023-39999 Moyenne · 4,3
WordPress

WordPress Core <= 6.3.1 – Authenticated(Contributor+) Sensitive Information Exposure via Comments on Protected Posts

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.3.1 via the comments listing. This allows authenticated users, with contributor-level privileges or above, to view comments on protected posts.

Versions affectées

*-4.1.38, 4.2-4.2.35, 4.3-4.3.31, 4.4-4.4.30, 4.5-4.5.29, 4.6-4.6.26, 4.7-4.7.26, 4.8-4.8.22, 4.9-4.9.23, 5.0-5.0.19, 5.1-5.1.16, 5.2-5.2.18, 5.3-5.3.15, 5.4-5.4.13, 5.5-5.5.12, 5.6-5.6.11, 5.7-5.7.9, 5.8-5.8.7, 5.9-5.9.7, 6.0-6.0.5, 6.1-6.1.3, 6.2-6.2.2, 6.3-6.3.1

Correctif

4.1.39, 4.2.36, 4.3.32, 4.4.31, 4.5.30, 4.6.27, 4.7.27, 4.8.23, 4.9.24, 5.0.20, 5.1.17, 5.2.19, 5.3.16, 5.4.14, 5.5.13, 5.6.12, 5.7.10, 5.8.8, 5.9.8, 6.0.6, 6.1.4, 6.2.3, 6.3.2

Publication

12/10/2023

CVE-2023-5561 Moyenne · 5,3
WordPress

WordPress Core 4.7.0 – 6.3.1 – Sensitive Information Exposure via User Search REST Endpoint

WordPress Core is vulnerable to Sensitive Information Exposure in versions between 4.7.0 and 6.3.1 via the User REST endpoint. While the search results do not display user email addresses unless the requesting user has the 'list_users' capability, the…

Versions affectées

4.7-4.7.26, 4.8-4.8.22, 4.9-4.9.23, 5.0-5.0.19, 5.1-5.1.16, 5.2-5.2.18, 5.3-5.3.15, 5.4-5.4.13, 5.5-5.5.12, 5.6-5.6.11, 5.7-5.7.9, 5.8-5.8.7, 5.9-5.9.7, 6.0-6.0.5, 6.1-6.1.3, 6.2-6.2.2, 6.3-6.3.1

Correctif

4.7.27, 4.8.23, 4.9.24, 5.0.20, 5.1.17, 5.2.19, 5.3.16, 5.4.14, 5.5.13, 5.6.12, 5.7.10, 5.8.8, 5.9.8, 6.0.6, 6.1.4, 6.2.3, 6.3.2

Publication

12/10/2023

Vulnérabilité Moyenne · 5,4
WordPress

WordPress Core < 6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode

WordPress Core is vulnerable to arbitrary shortcode execution in versions up to, and including, 6.3.1 due to a lack of input validation on the 'shortcode' parameter in the parse_media_shortcode AJAX function. This allows authenticated attackers, with subscriber-level privileges…

Versions affectées

*-4.1.38, 4.2-4.2.35, 4.3-4.3.31, 4.4-4.4.30, 4.5-4.5.29, 4.6-4.6.26, 4.7-4.7.26, 4.8-4.8.22, 4.9-4.9.23, 5.0-5.0.19, 5.1-5.1.16, 5.2-5.2.18, 5.3-5.3.15, 5.4-5.4.13, 5.5-5.5.12, 5.6-5.6.11, 5.7-5.7.9, 5.8-5.8.7, 5.9-5.9.7, 6.0-6.0.5, 6.1-6.1.3, 6.2-6.2.2, 6.3-6.3.1

Correctif

4.1.39, 4.2.36, 4.3.32, 4.4.31, 4.5.30, 4.6.27, 4.7.27, 4.8.23, 4.9.24, 5.0.20, 5.1.17, 5.2.19, 5.3.16, 5.4.14, 5.5.13, 5.6.12, 5.7.10, 5.8.8, 5.9.8, 6.0.6, 6.1.4, 6.2.3, 6.3.2

Publication

12/10/2023

Vulnérabilité Moyenne · 6,5
WordPress

WordPress Core < 6.2.1 – Shortcode Execution in User Generated Content

WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2. This could allow unauthenticated attackers to execute shortcodes via submitting comments or other content, allowing them to exploit vulnerabilities that typically…

Versions affectées

[5.9, 5.9.6), [6.0, 6.0.4), [6.1, 6.1.2), [6.2, 6.2.1)

Correctif

5.9.6, 6.0.4, 6.1.2, 6.2.1

Publication

19/05/2023

Vulnérabilité Moyenne · 6,5
WordPress

WordPress Core < 6.2.2 – Shortcode Execution in User Generated Content

WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2.1. This could allow unauthenticated attackers to execute shortcodes via submitting comments or other content, allowing them to exploit vulnerabilities that typically…

Versions affectées

[5.9, 5.9.7), [6.0, 6.0.5), [6.1, 6.1.3), [6.2, 6.2.2)

Correctif

5.9.7, 6.0.5, 6.1.3, 6.2.2

Publication

19/05/2023

Vulnérabilité Moyenne · 6,4
WordPress

WordPress Core < 6.2.1 – Insufficient Sanitization of Block Attributes

WordPress Core failed to sufficiently sanitize block attributes in versions up to, and including, 6.2. This makes it possible for authenticated attackers with contributor-level and above permissions to embed arbitrary content in HTML comments on the page, though…

Versions affectées

[*, 4.1), [4.1, 4.1.38), [4.2, 4.2.35), [4.3, 4.3.31), [4.4, 4.4.30), [4.5, 4.5.29), [4.6, 4.6.26), [4.7, 4.7.26), [4.8, 4.8.22), [4.9, 4.9.23), [5.0, 5.0.19), [5.1, 5.1.16), [5.2, 5.2.18), [5.3, 5.3.15), [5.4, 5.4.13), [5.5, 5.5.12), [5.6, 5.6.11), [5.7, 5.7.9), [5.8, 5.8.7), [5.9, 5.9.6), [6.0, 6.0.4), [6.1, 6.1.2), [6.2, 6.2.1)

Correctif

4.1.38, 4.2.35, 4.3.31, 4.4.30, 4.5.29, 4.6.26, 4.7.26, 4.8.22, 4.9.23, 5.0.19, 5.1.16, 5.2.18, 5.3.15, 5.4.13, 5.5.12, 5.6.11, 5.7.9, 5.8.7, 5.9.6, 6.0.4, 6.1.2, 6.2.1

Publication

16/05/2023

CVE-2023-2745 Moyenne · 5,4
WordPress

WordPress Core < 6.2.1 – Directory Traversal

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload…

Versions affectées

[*, 4.1.38), [4.2, 4.2.35), [4.3, 4.3.31), [4.4, 4.4.30), [4.5, 4.5.29), [4.6, 4.6.26), [4.7, 4.7.26), [4.8, 4.8.22), [4.9, 4.9.23), [5.0, 5.0.19), [5.1, 5.1.16), [5.2, 5.2.18), [5.3, 5.3.15), [5.4, 5.4.13), [5.5, 5.5.12), [5.6, 5.6.11), [5.7, 5.7.9), [5.8, 5.8.7), [5.9, 5.9.6), [6.0, 6.0.4), [6.1, 6.1.2), [6.2, 6.2.1)

Correctif

4.1.38, 4.2.35, 4.3.31, 4.4.30, 4.5.29, 4.6.26, 4.7.26, 4.8.22, 4.9.23, 5.0.19, 5.1.16, 5.2.18, 5.3.15, 5.4.13, 5.5.12, 5.6.11, 5.7.9, 5.8.7, 5.9.6, 6.0.4, 6.1.2, 6.2.1

Publication

16/05/2023

Vulnérabilité Moyenne · 6,4
WordPress

WordPress Core < 6.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Embed Discovery

WordPress Core is vulnerable to stored Cross-Site Scripting in versions up to, and including, 6.2, due to insufficient validation of the protocol in the response when processing oEmbed discovery. This makes it possible for authenticated attackers with contributor-level…

Versions affectées

[*, 4.1.38), [4.2, 4.2.35), [4.3, 4.3.31), [4.4, 4.4.30), [4.5, 4.5.29), [4.6, 4.6.26), [4.7, 4.7.26), [4.8, 4.8.22), [4.9, 4.9.23), [5.0, 5.0.19), [5.1, 5.1.16), [5.2, 5.2.18), [5.3, 5.3.15), [5.4, 5.4.13), [5.5, 5.5.12), [5.6, 5.6.11), [5.7, 5.7.9), [5.8, 5.8.7), [5.9, 5.9.6), [6.0, 6.0.4), [6.1, 6.1.2), [6.2, 6.2.1)

Correctif

4.1.38, 4.2.35, 4.3.31, 4.4.30, 4.5.29, 4.6.26, 4.7.26, 4.8.22, 4.9.23, 5.0.19, 5.1.16, 5.2.18, 5.3.15, 5.4.13, 5.5.12, 5.6.11, 5.7.9, 5.8.7, 5.9.6, 6.0.4, 6.1.2, 6.2.1

Publication

16/05/2023

Vulnérabilité Moyenne · 4,3
WordPress

WordPress Core < 6.2.1 – Cross-Site Request Forgery

WordPress Core is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the ‘wp_ajax_set_attachment_thumbnail’ AJAX function in versions up to, and including, 6.2. This allows unauthenticated users to update the thumbnail image associated with existing attachments,…

Versions affectées

[*, 4.1), [4.1, 4.1.38), [4.2, 4.2.35), [4.3, 4.3.31), [4.4, 4.4.30), [4.5, 4.5.29), [4.6, 4.6.26), [4.7, 4.7.26), [4.8, 4.8.22), [4.9, 4.9.23), [5.0, 5.0.19), [5.1, 5.1.16), [5.2, 5.2.18), [5.3, 5.3.15), [5.4, 5.4.13), [5.5, 5.5.12), [5.6, 5.6.11), [5.7, 5.7.9), [5.8, 5.8.7), [5.9, 5.9.6), [6.0, 6.0.4), [6.1, 6.1.2), [6.2, 6.2.1)

Correctif

4.1.38, 4.2.35, 4.3.31, 4.4.30, 4.5.29, 4.6.26, 4.7.26, 4.8.22, 4.9.23, 5.0.19, 5.1.16, 5.2.18, 5.3.15, 5.4.13, 5.5.12, 5.6.11, 5.7.9, 5.8.7, 5.9.6, 6.0.4, 6.1.2, 6.2.1

Publication

16/05/2023

CVE-2022-43500 Moyenne · 6,4
WordPress

WordPress Core < 6.0.3 & Gutenberg < 14.3.1 – Authenticated Cross-Site Scripting in Various Blocks

WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to Stored Cross-Site Scripting due to insufficient output escaping on user supplied input. The RSS widget, Search Block,…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

CVE-2022-43504 Élevée · 7,2
WordPress

WordPress Core < 6.0.3 – Stored Cross-Site Scripting via wp-mail.php

WordPress Core in versions up to 6.0.3 are vulnerable to Cross-Site Scripting via wp-mail.php. This is due to no validation on what level the user was sending the email post and therefore did not perform any sanitization on…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

Vulnérabilité Critique · 9,8
WordPress

WordPress Core < 6.0.3 – SQL Injection via WP_Date_Query

WordPress Core is vulnerable to SQL Injection in versions up to 6.0.3. This is due to insufficient escaping on where “AND” and “OR” present in the query. This may make it possible for attackers to achieve SQL Injection…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

Vulnérabilité Moyenne · 5,5
WordPress

WordPress Core < 6.0.3 – Authenticated (Editor+) Stored Cross-Site Scripting via Comments

WordPress Core is vulnerable to Stored Cross-Site Scripting, exploitable during comment editing, in versions up to 6.0.3. This is due to insufficient escaping and sanitization on the values being stored during a comment update. This makes it possible…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

CVE-2022-43504 Moyenne · 5,3
WordPress

WordPress Core < 6.0.3 – Information Disclosure (Email Address)

WordPress Core is vulnerable to Information Disclosure of in versions up to 6.0.3. When the post by email functionality is enabled, it may log post author's email addresses in a way that may be publicly accessible. This could…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

Vulnérabilité Élevée · 8,8
WordPress

WordPress Core < 6.0.3 – Cross-Site Request Forgery via wp-trackback.php

WordPress Core is vulnerable to Cross-Site Request Forgery via wp-trackback.php in versions up to 6.0.3. This is due to the fact that the any request to wp-trackback.php would assume the identity of the user whose cookies are sent…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

CVE-2022-43497 Élevée · 8,8
WordPress

WordPress Core < 6.0.3 – Reflected Cross-Site Scripting via SQL Injection

WordPress Core is vulnerable to SQL Injection in the Media Library that can be leveraged to exploit a Reflected Cross-Site Scripting issue in versions up to 6.0.3. This is due to insufficient escaping on user supplied values passed…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

Vulnérabilité Moyenne · 4,3
WordPress

WordPress Core < 6.0.3 – Authenticated Information Disclosure via REST-API

WordPress Core is vulnerable to information disclosure via the REST-API in versions up to 6.0.3. The REST API endpoint for terms and tags did not perform enough validation on the user requesting information about terms and tags for…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

Vulnérabilité Moyenne · 5,5
WordPress

WordPress Core < 6.0.3 – Authenticated (Admin+) Stored Cross-Site Scripting via Customizer

WordPress Core is vulnerable to Stored Cross-Site Scripting via the Customizer in versions up to 6.0.3. This is due to insufficient escaping on the 'Blog Name' value that could be edited and become executable with the right payload…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

Vulnérabilité Faible · 3,7
WordPress

WordPress Core < 6.0.3 – Information Disclosure (Multi-Part Email Leak)

WordPress Core is vulnerable to information disclosure via a REST-API endpoint in versions up to 6.0.3. The endpoint for terms and tags did not perform enough validation on the user requesting information about terms and tags for a…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

Vulnérabilité Moyenne · 5,4
WordPress

WordPress Core < 6.0.3 – Open Redirect

WordPress Core is vulnerable to open redirect in versions up to 6.0.3. This is due to insufficient validation of the 'Referer' header and _wp_http_referer request parameter when a user accesses a link with an expired or invalid nonce.…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités