Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 2

Consultez 389 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 2 de l’annuaire.

389Vulnérabilités
17Critiques
387Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

CVE-2024-6307 Moyenne · 6,4
WordPress

WordPress Core < 6.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API

WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to insufficient input sanitization and output escaping on URLs. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

5.9-5.9.9, 6.0-6.0.8, 6.1-6.1.6, 6.2-6.2.5, 6.3-6.3.4, 6.4-6.4.4, 6.5-6.5.4

Correctif

5.9.10, 6.0.9, 6.1.7, 6.2.6, 6.3.5, 6.4.5, 6.5.5

Publication

24/06/2024

CVE-2024-32111 Moyenne · 4,3
WordPress

WordPress Core < 6.5.5 – Authenticated (Contributor+) Directory Traversal

WordPress Core is vulnerable to Directory Traversal in various versions up to 6.5.5 via the Template Part block. This makes it possible for authenticated attackers, with Contributor-level access and above, to include arbitrary HTML Files on sites running…

Versions affectées

[*, 4.1), 4.1-4.1.40, 4.2-4.2.37, 4.3-4.3.33, 4.4-4.4.32, 4.5-4.5.31, 4.6-4.6.28, 4.7-4.7.28, 4.8-4.8.24, 4.9-4.9.25, 5.0-5.0.21, 5.1-5.1.18, 5.2-5.2.20, 5.3-5.3.17, 5.4-5.4.15, 5.5-5.5.14, 5.6-5.6.13, 5.7-5.7.11, 5.8-5.8.9, 5.9-5.9.9, 6.0-6.0.8, 6.1-6.1.6, 6.2-6.2.5, 6.3-6.3.4, 6.4-6.4.4, 6.5-6.5.4

Correctif

4.1.41, 4.2.38, 4.3.34, 4.4.33, 4.5.32, 4.6.29, 4.7.29, 4.8.25, 4.9.26, 5.0.22, 5.1.19, 5.2.21, 5.3.18, 5.4.16, 5.5.15, 5.6.14, 5.7.12, 5.8.10, 5.9.10, 6.0.9, 6.1.7, 6.2.6, 6.3.5, 6.4.5, 6.5.5

Publication

24/06/2024

CVE-2024-4439 Élevée · 7,2
WordPress

WordPress Core < 6.5.2 – Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block

WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers,…

Versions affectées

6.0-6.0.7, 6.1-6.1.5, 6.2-6.2.4, 6.3-6.3.3, 6.4-6.4.3, 6.5-6.5.1

Correctif

6.0.8, 6.1.6, 6.2.5, 6.3.4, 6.4.4, 6.5.2

Publication

09/04/2024

CVE-2023-5692 Informationnelle
WordPress

WordPress Core <= 6.4.3 – Sensitive Information Exposure via redirect_guess_404_permalink

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been…

Versions affectées

*-6.4.3

Correctif

6.5

Publication

04/04/2024

CVE-2023-38000 Moyenne · 6,4
WordPress

WordPress Core 5.9-6.3.1 – Authenticated(Contributor+) Stored Cross-Site Scripting via Navigation Attributes

WordPress Core is vulnerable to Stored Cross-Site Scripting via the arrow navigation block attributes in versions between 5.9 and 6.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level privileges…

Versions affectées

5.9-5.9.7, 6.0-6.0.5, 6.1-6.1.3, 6.2-6.2.2, 6.3-6.3.1

Correctif

5.9.8, 6.0.6, 6.1.4, 6.2.3, 6.3.2

Publication

12/10/2023

Vulnérabilité Moyenne · 5,3
WordPress

WordPress Core 4.7.0-6.3.1 – Denial of Service via Cache Poisoning

WordPress Core is vulnerable to Denial of Service via Cache Poisoning in versions between 4.7.0 and 6.3.1. In cases where the X-HTTP-Method-Override header was sent in a request to a REST endpoint and the endpoint returned a 4xx…

Versions affectées

4.7-4.7.26, 4.8-4.8.22, 4.9-4.9.23, 5.0-5.0.19, 5.1-5.1.16, 5.2-5.2.18, 5.3-5.3.15, 5.4-5.4.13, 5.5-5.5.12, 5.6-5.6.11, 5.7-5.7.9, 5.8-5.8.7, 5.9-5.9.7, 6.0-6.0.5, 6.1-6.1.3, 6.2-6.2.2, 6.3-6.3.1

Correctif

4.7.27, 4.8.23, 4.9.24, 5.0.20, 5.1.17, 5.2.19, 5.3.16, 5.4.14, 5.5.13, 5.6.12, 5.7.10, 5.8.8, 5.9.8, 6.0.6, 6.1.4, 6.2.3, 6.3.2

Publication

12/10/2023

Vulnérabilité Moyenne · 6,1
WordPress

WordPress Core 5.6 – 6.3.1 – Reflected Cross-Site Scripting via Application Password Requests

WordPress Core is vulnerable to Reflected Cross-Site Scripting via the ‘success_url’ and 'reject_url' parameters when requesting application passwords in versions between 5.6 and 6.3.1 due to insufficient input sanitization and output escaping of pseudo protocol URIs. This makes…

Versions affectées

5.6-5.6.11, 5.7-5.7.9, 5.8-5.8.7, 5.9-5.9.7, 6.0-6.0.5, 6.1-6.1.3, 6.2-6.2.2, 6.3-6.3.1

Correctif

5.6.12, 5.7.10, 5.8.8, 5.9.8, 6.0.6, 6.1.4, 6.2.3, 6.3.2

Publication

12/10/2023

CVE-2023-39999 Moyenne · 4,3
WordPress

WordPress Core <= 6.3.1 – Authenticated(Contributor+) Sensitive Information Exposure via Comments on Protected Posts

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.3.1 via the comments listing. This allows authenticated users, with contributor-level privileges or above, to view comments on protected posts.

Versions affectées

*-4.1.38, 4.2-4.2.35, 4.3-4.3.31, 4.4-4.4.30, 4.5-4.5.29, 4.6-4.6.26, 4.7-4.7.26, 4.8-4.8.22, 4.9-4.9.23, 5.0-5.0.19, 5.1-5.1.16, 5.2-5.2.18, 5.3-5.3.15, 5.4-5.4.13, 5.5-5.5.12, 5.6-5.6.11, 5.7-5.7.9, 5.8-5.8.7, 5.9-5.9.7, 6.0-6.0.5, 6.1-6.1.3, 6.2-6.2.2, 6.3-6.3.1

Correctif

4.1.39, 4.2.36, 4.3.32, 4.4.31, 4.5.30, 4.6.27, 4.7.27, 4.8.23, 4.9.24, 5.0.20, 5.1.17, 5.2.19, 5.3.16, 5.4.14, 5.5.13, 5.6.12, 5.7.10, 5.8.8, 5.9.8, 6.0.6, 6.1.4, 6.2.3, 6.3.2

Publication

12/10/2023

CVE-2023-5561 Moyenne · 5,3
WordPress

WordPress Core 4.7.0 – 6.3.1 – Sensitive Information Exposure via User Search REST Endpoint

WordPress Core is vulnerable to Sensitive Information Exposure in versions between 4.7.0 and 6.3.1 via the User REST endpoint. While the search results do not display user email addresses unless the requesting user has the 'list_users' capability, the…

Versions affectées

4.7-4.7.26, 4.8-4.8.22, 4.9-4.9.23, 5.0-5.0.19, 5.1-5.1.16, 5.2-5.2.18, 5.3-5.3.15, 5.4-5.4.13, 5.5-5.5.12, 5.6-5.6.11, 5.7-5.7.9, 5.8-5.8.7, 5.9-5.9.7, 6.0-6.0.5, 6.1-6.1.3, 6.2-6.2.2, 6.3-6.3.1

Correctif

4.7.27, 4.8.23, 4.9.24, 5.0.20, 5.1.17, 5.2.19, 5.3.16, 5.4.14, 5.5.13, 5.6.12, 5.7.10, 5.8.8, 5.9.8, 6.0.6, 6.1.4, 6.2.3, 6.3.2

Publication

12/10/2023

Vulnérabilité Moyenne · 5,4
WordPress

WordPress Core < 6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via parse-media-shortcode

WordPress Core is vulnerable to arbitrary shortcode execution in versions up to, and including, 6.3.1 due to a lack of input validation on the 'shortcode' parameter in the parse_media_shortcode AJAX function. This allows authenticated attackers, with subscriber-level privileges…

Versions affectées

*-4.1.38, 4.2-4.2.35, 4.3-4.3.31, 4.4-4.4.30, 4.5-4.5.29, 4.6-4.6.26, 4.7-4.7.26, 4.8-4.8.22, 4.9-4.9.23, 5.0-5.0.19, 5.1-5.1.16, 5.2-5.2.18, 5.3-5.3.15, 5.4-5.4.13, 5.5-5.5.12, 5.6-5.6.11, 5.7-5.7.9, 5.8-5.8.7, 5.9-5.9.7, 6.0-6.0.5, 6.1-6.1.3, 6.2-6.2.2, 6.3-6.3.1

Correctif

4.1.39, 4.2.36, 4.3.32, 4.4.31, 4.5.30, 4.6.27, 4.7.27, 4.8.23, 4.9.24, 5.0.20, 5.1.17, 5.2.19, 5.3.16, 5.4.14, 5.5.13, 5.6.12, 5.7.10, 5.8.8, 5.9.8, 6.0.6, 6.1.4, 6.2.3, 6.3.2

Publication

12/10/2023

Vulnérabilité Moyenne · 6,5
WordPress

WordPress Core < 6.2.1 – Shortcode Execution in User Generated Content

WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2. This could allow unauthenticated attackers to execute shortcodes via submitting comments or other content, allowing them to exploit vulnerabilities that typically…

Versions affectées

[5.9, 5.9.6), [6.0, 6.0.4), [6.1, 6.1.2), [6.2, 6.2.1)

Correctif

5.9.6, 6.0.4, 6.1.2, 6.2.1

Publication

19/05/2023

Vulnérabilité Moyenne · 6,5
WordPress

WordPress Core < 6.2.2 – Shortcode Execution in User Generated Content

WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2.1. This could allow unauthenticated attackers to execute shortcodes via submitting comments or other content, allowing them to exploit vulnerabilities that typically…

Versions affectées

[5.9, 5.9.7), [6.0, 6.0.5), [6.1, 6.1.3), [6.2, 6.2.2)

Correctif

5.9.7, 6.0.5, 6.1.3, 6.2.2

Publication

19/05/2023

Vulnérabilité Moyenne · 6,4
WordPress

WordPress Core < 6.2.1 – Insufficient Sanitization of Block Attributes

WordPress Core failed to sufficiently sanitize block attributes in versions up to, and including, 6.2. This makes it possible for authenticated attackers with contributor-level and above permissions to embed arbitrary content in HTML comments on the page, though…

Versions affectées

[*, 4.1), [4.1, 4.1.38), [4.2, 4.2.35), [4.3, 4.3.31), [4.4, 4.4.30), [4.5, 4.5.29), [4.6, 4.6.26), [4.7, 4.7.26), [4.8, 4.8.22), [4.9, 4.9.23), [5.0, 5.0.19), [5.1, 5.1.16), [5.2, 5.2.18), [5.3, 5.3.15), [5.4, 5.4.13), [5.5, 5.5.12), [5.6, 5.6.11), [5.7, 5.7.9), [5.8, 5.8.7), [5.9, 5.9.6), [6.0, 6.0.4), [6.1, 6.1.2), [6.2, 6.2.1)

Correctif

4.1.38, 4.2.35, 4.3.31, 4.4.30, 4.5.29, 4.6.26, 4.7.26, 4.8.22, 4.9.23, 5.0.19, 5.1.16, 5.2.18, 5.3.15, 5.4.13, 5.5.12, 5.6.11, 5.7.9, 5.8.7, 5.9.6, 6.0.4, 6.1.2, 6.2.1

Publication

16/05/2023

CVE-2023-2745 Moyenne · 5,4
WordPress

WordPress Core < 6.2.1 – Directory Traversal

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload…

Versions affectées

[*, 4.1.38), [4.2, 4.2.35), [4.3, 4.3.31), [4.4, 4.4.30), [4.5, 4.5.29), [4.6, 4.6.26), [4.7, 4.7.26), [4.8, 4.8.22), [4.9, 4.9.23), [5.0, 5.0.19), [5.1, 5.1.16), [5.2, 5.2.18), [5.3, 5.3.15), [5.4, 5.4.13), [5.5, 5.5.12), [5.6, 5.6.11), [5.7, 5.7.9), [5.8, 5.8.7), [5.9, 5.9.6), [6.0, 6.0.4), [6.1, 6.1.2), [6.2, 6.2.1)

Correctif

4.1.38, 4.2.35, 4.3.31, 4.4.30, 4.5.29, 4.6.26, 4.7.26, 4.8.22, 4.9.23, 5.0.19, 5.1.16, 5.2.18, 5.3.15, 5.4.13, 5.5.12, 5.6.11, 5.7.9, 5.8.7, 5.9.6, 6.0.4, 6.1.2, 6.2.1

Publication

16/05/2023

Vulnérabilité Moyenne · 6,4
WordPress

WordPress Core < 6.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Embed Discovery

WordPress Core is vulnerable to stored Cross-Site Scripting in versions up to, and including, 6.2, due to insufficient validation of the protocol in the response when processing oEmbed discovery. This makes it possible for authenticated attackers with contributor-level…

Versions affectées

[*, 4.1.38), [4.2, 4.2.35), [4.3, 4.3.31), [4.4, 4.4.30), [4.5, 4.5.29), [4.6, 4.6.26), [4.7, 4.7.26), [4.8, 4.8.22), [4.9, 4.9.23), [5.0, 5.0.19), [5.1, 5.1.16), [5.2, 5.2.18), [5.3, 5.3.15), [5.4, 5.4.13), [5.5, 5.5.12), [5.6, 5.6.11), [5.7, 5.7.9), [5.8, 5.8.7), [5.9, 5.9.6), [6.0, 6.0.4), [6.1, 6.1.2), [6.2, 6.2.1)

Correctif

4.1.38, 4.2.35, 4.3.31, 4.4.30, 4.5.29, 4.6.26, 4.7.26, 4.8.22, 4.9.23, 5.0.19, 5.1.16, 5.2.18, 5.3.15, 5.4.13, 5.5.12, 5.6.11, 5.7.9, 5.8.7, 5.9.6, 6.0.4, 6.1.2, 6.2.1

Publication

16/05/2023

Vulnérabilité Moyenne · 4,3
WordPress

WordPress Core < 6.2.1 – Cross-Site Request Forgery

WordPress Core is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the ‘wp_ajax_set_attachment_thumbnail’ AJAX function in versions up to, and including, 6.2. This allows unauthenticated users to update the thumbnail image associated with existing attachments,…

Versions affectées

[*, 4.1), [4.1, 4.1.38), [4.2, 4.2.35), [4.3, 4.3.31), [4.4, 4.4.30), [4.5, 4.5.29), [4.6, 4.6.26), [4.7, 4.7.26), [4.8, 4.8.22), [4.9, 4.9.23), [5.0, 5.0.19), [5.1, 5.1.16), [5.2, 5.2.18), [5.3, 5.3.15), [5.4, 5.4.13), [5.5, 5.5.12), [5.6, 5.6.11), [5.7, 5.7.9), [5.8, 5.8.7), [5.9, 5.9.6), [6.0, 6.0.4), [6.1, 6.1.2), [6.2, 6.2.1)

Correctif

4.1.38, 4.2.35, 4.3.31, 4.4.30, 4.5.29, 4.6.26, 4.7.26, 4.8.22, 4.9.23, 5.0.19, 5.1.16, 5.2.18, 5.3.15, 5.4.13, 5.5.12, 5.6.11, 5.7.9, 5.8.7, 5.9.6, 6.0.4, 6.1.2, 6.2.1

Publication

16/05/2023

CVE-2022-43500 Moyenne · 6,4
WordPress

WordPress Core < 6.0.3 & Gutenberg < 14.3.1 – Authenticated Cross-Site Scripting in Various Blocks

WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to Stored Cross-Site Scripting due to insufficient output escaping on user supplied input. The RSS widget, Search Block,…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

CVE-2022-43504 Élevée · 7,2
WordPress

WordPress Core < 6.0.3 – Stored Cross-Site Scripting via wp-mail.php

WordPress Core in versions up to 6.0.3 are vulnerable to Cross-Site Scripting via wp-mail.php. This is due to no validation on what level the user was sending the email post and therefore did not perform any sanitization on…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités