Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 3

Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 3 de l’annuaire.

380Vulnérabilités
17Critiques
378Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

Vulnérabilité Faible · 3,7
WordPress

WordPress Core < 6.0.3 – Shared User Instance Weakness

WordPress Core in versions up to 6.0.3 had a weakness in how Share User Instances were handled. This fix appears to have been necessary to safely use the wp_set_current_user( 0 ); method to patch the previously mentioned XSS…

Versions affectées

*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2

Correctif

3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

Publication

18/10/2022

CVE-2022-4973 Moyenne · 4,9
WordPress

WordPress Core < 6.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it…

Versions affectées

*-3.6.1, 3.7-3.7.38, 3.8-3.8.38, 3.9-3.9.36, 4.0-4.0.35, 4.1-4.1.35, 4.2-4.2.32, 4.3-4.3.28, 4.4-4.4.27, 4.5-4.5.26, 4.6-4.6.23, 4.7-4.7.23, 4.8-4.8.19, 4.9-4.9.20, 5.0-5.0.16, 5.1-5.1.13, 5.2-5.2.15, 5.3-5.3.12, 5.4-5.4.10, 5.5-5.5.9, 5.6-5.6.8, 5.7-5.7.6, 5.8-5.8.4, 5.9-5.9.3, 6.0-6.0.1

Correctif

3.7.39, 3.8.39, 3.9.37, 4.0.36, 4.1.36, 4.2.33, 4.3.29, 4.4.28, 4.5.27, 4.6.24, 4.7.24, 4.8.20, 4.9.21, 5.0.17, 5.1.14, 5.2.16, 5.3.13, 5.4.11, 5.5.10, 5.6.9, 5.7.7, 5.8.5, 5.9.4, 6.0.2

Publication

30/08/2022

Vulnérabilité Moyenne · 4,4
WordPress

WordPress Core < 6.0.2 – Stored Cross-Site Scripting via Plugin Deactivation and Deletion Errors

WordPress Core, in versions up to 6.0.2, is vulnerable to Stored Cross-Site Scripting that can be exploited when malicious content is injected into plugin code that triggers when an error occurs during plugin de-activation or during deletion. This…

Versions affectées

*-3.6.1, 3.7-3.7.38, 3.8-3.8.38, 3.9-3.9.36, 4.0-4.0.35, 4.1-4.1.35, 4.2-4.2.32, 4.3-4.3.28, 4.4-4.4.27, 4.5-4.5.26, 4.6-4.6.23, 4.7-4.7.23, 4.8-4.8.19, 4.9-4.9.20, 5.0-5.0.16, 5.1-5.1.13, 5.2-5.2.15, 5.3-5.3.12, 5.4-5.4.10, 5.5-5.5.9, 5.6-5.6.8, 5.7-5.7.6, 5.8-5.8.4, 5.9-5.9.3, 6.0-6.0.1

Correctif

3.7.39, 3.8.39, 3.9.37, 4.0.36, 4.1.36, 4.2.33, 4.3.29, 4.4.28, 4.5.27, 4.6.24, 4.7.24, 4.8.20, 4.9.21, 5.0.17, 5.1.14, 5.2.16, 5.3.13, 5.4.11, 5.5.10, 5.6.9, 5.7.7, 5.8.5, 5.9.4, 6.0.2

Publication

30/08/2022

Vulnérabilité Élevée · 8,0
WordPress

WordPress Core < 6.0.2 – Authenticated SQL Injection

WordPress Core, in versions up to 6.0.2, is vulnerable to SQL Injection that can be exploited by authenticated users via the LIMIT parameter passed through the get_bookmarks function. This can be exploited on default WordPress installations by users…

Versions affectées

*-3.6.1, 3.7-3.7.38, 3.8-3.8.38, 3.9-3.9.36, 4.0-4.0.35, 4.1-4.1.35, 4.2-4.2.32, 4.3-4.3.28, 4.4-4.4.27, 4.5-4.5.26, 4.6-4.6.23, 4.7-4.7.23, 4.8-4.8.19, 4.9-4.9.20, 5.0-5.0.16, 5.1-5.1.13, 5.2-5.2.15, 5.3-5.3.12, 5.4-5.4.10, 5.5-5.5.9, 5.6-5.6.8, 5.7-5.7.6, 5.8-5.8.4, 5.9-5.9.3, 6.0-6.0.1

Correctif

3.7.39, 3.8.39, 3.9.37, 4.0.36, 4.1.36, 4.2.33, 4.3.29, 4.4.28, 4.5.27, 4.6.24, 4.7.24, 4.8.20, 4.9.21, 5.0.17, 5.1.14, 5.2.16, 5.3.13, 5.4.11, 5.5.10, 5.6.9, 5.7.7, 5.8.5, 5.9.4, 6.0.2

Publication

30/08/2022

CVE-2021-20083 Élevée · 8,8
WordPress

WordPress Core < 5.9.1 – jQuery Prototype Pollution

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.

Versions affectées

[*, 3.7), 3.7-3.7.37, 3.8-3.8.37, 3.9-3.9.35, 4.0-4.0.34, 4.1-4.1.34, 4.2-4.2.31, 4.3-4.3.27, 4.4-4.4.26, 4.5-4.5.25, 4.6-4.6.22, 4.7-4.7.22, 4.8-4.8.18, 4.9-4.9.19, 5.0-5.0.15, 5.1-5.1.12, 5.2-5.2.14, 5.3-5.3.11, 5.4-5.4.9, 5.5-5.5.8, 5.6-5.6.7, 5.7-5.7.5, 5.8-5.8.3, 5.9-5.9.1

Correctif

3.7.38, 3.8.38, 3.9.36, 4.0.35, 4.1.35, 4.2.32, 4.3.28, 4.4.27, 4.5.26, 4.6.23, 4.7.23, 4.8.19, 4.9.20, 5.0.16, 5.1.13, 5.2.15, 5.3.12, 5.4.10, 5.5.9, 5.6.8, 5.7.6, 5.8.4, 5.9.2

Publication

11/03/2022

Vulnérabilité Moyenne · 5,4
WordPress

WordPress Core < 5.9.2 & Gutenberg < 12.7.2 – Prototype Pollution via Block Editor

WordPress Core in various versions < 5.9.2 and Gutenberg versions less than 12.7.2 are vulnerable to prototype pollution via the block editor which could make injecting malicious web scripts possible in some cases.

Versions affectées

[*, 3.7), 3.7-3.7.37, 3.8-3.8.37, 3.9-3.9.35, 4.0-4.0.34, 4.1-4.1.34, 4.2-4.2.31, 4.3-4.3.27, 4.4-4.4.26, 4.5-4.5.25, 4.6-4.6.22, 4.7-4.7.22, 4.8-4.8.18, 4.9-4.9.19, 5.0-5.0.15, 5.1-5.1.12, 5.2-5.2.14, 5.3-5.3.11, 5.4-5.4.9, 5.5-5.5.8, 5.6-5.6.7, 5.7-5.7.5, 5.8-5.8.3, 5.9-5.9.1

Correctif

3.7.38, 3.8.38, 3.9.36, 4.0.35, 4.1.35, 4.2.32, 4.3.28, 4.4.27, 4.5.26, 4.6.23, 4.7.23, 4.8.19, 4.9.20, 5.0.16, 5.1.13, 5.2.15, 5.3.12, 5.4.10, 5.5.9, 5.6.8, 5.7.6, 5.8.4, 5.9.2

Publication

11/03/2022

CVE-2022-21662 Élevée · 8,0
WordPress

WordPress Core < 5.8.3 – Authenticated (Author+) Stored Cross Site Scripting

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged…

Versions affectées

[3.7, 3.7.37), [3.8, 3.8.37), [3.9, 3.9.35), [4.0, 4.0.34), [4.1, 4.1.34), [4.2, 4.2.31), [4.3, 4.3.27), [4.4, 4.4.26), [4.5, 4.5.25), [4.6, 4.6.22), [4.7, 4.7.22), [4.8, 4.8.18), [4.9, 4.9.19), [5.0, 5.0.15), [5.1, 5.1.12), [5.2, 5.2.14), [5.3, 5.3.11), [5.4, 5.4.9), [5.5, 5.5.8), [5.6, 5.6.7), [5.7, 5.7.5), [5.8, 5.8.3)

Correctif

3.7.37, 3.8.37, 3.9.35, 4.0.34, 4.1.34, 4.2.31, 4.3.27, 4.4.26, 4.5.25, 4.6.22, 4.7.22, 4.8.18, 4.9.19, 5.0.15, 5.1.12, 5.2.14, 5.3.11, 5.4.9, 5.5.8, 5.6.7, 5.7.5, 5.8.3

Publication

06/01/2022

CVE-2022-21663 Moyenne · 6,6
WordPress

WordPress Core < 5.8.3 – Super Admin Multi-Site Installation Object Injection

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has…

Versions affectées

[3.7, 3.7.37), [3.8, 3.8.37), [3.9, 3.9.35), [4.0, 4.0.34), [4.1, 4.1.34), [4.2, 4.2.31), [4.3, 4.3.27), [4.4, 4.4.26), [4.5, 4.5.25), [4.6, 4.6.22), [4.7, 4.7.22), [4.8, 4.8.18), [4.9, 4.9.19), [5.0, 5.0.15), [5.1, 5.1.12), [5.2, 5.2.14), [5.3, 5.3.11), [5.4, 5.4.9), [5.5, 5.5.8), [5.6, 5.6.7), [5.7, 5.7.5), [5.8, 5.8.3)

Correctif

3.7.37, 3.8.37, 3.9.35, 4.0.34, 4.1.34, 4.2.31, 4.3.27, 4.4.26, 4.5.25, 4.6.22, 4.7.22, 4.8.18, 4.9.19, 5.0.15, 5.1.12, 5.2.14, 5.3.11, 5.4.9, 5.5.8, 5.6.7, 5.7.5, 5.8.3

Publication

06/01/2022

CVE-2022-21664 Élevée · 7,4
WordPress

WordPress Core < 5.8.3 – SQL Injection via WP_Meta_Query

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed.…

Versions affectées

[4.1, 4.1.34), [4.2, 4.2.31), [4.3, 4.3.27), [4.4, 4.4.26), [4.5, 4.5.25), [4.6, 4.6.22), [4.7, 4.7.22), [4.8, 4.8.18), [4.9, 4.9.19), [5.0, 5.0.15), [5.1, 5.1.12), [5.2, 5.2.14), [5.3, 5.3.11), [5.4, 5.4.9), [5.5, 5.5.8), [5.6, 5.6.7), [5.7, 5.7.5), [5.8, 5.8.3)

Correctif

4.1.34, 4.2.31, 4.3.27, 4.4.26, 4.5.25, 4.6.22, 4.7.22, 4.8.18, 4.9.19, 5.0.15, 5.1.12, 5.2.14, 5.3.11, 5.4.9, 5.5.8, 5.6.7, 5.7.5, 5.8.3

Publication

06/01/2022

CVE-2021-44223 Informationnelle
WordPress

WordPress Core < 5.8 – Dependency Confusion

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies…

Versions affectées

*-5.7.5

Correctif

5.8

Publication

25/11/2021

Vulnérabilité Informationnelle
WordPress

WordPress Core < 5.8.2 – ca-bundle.crt contains expired certificate DST Root CA X3

WordPress Core in various versions less than version 5.8.2 contained an expired DST Root CA X3 certificate. There is no significant security risk to most WordPress users.

Versions affectées

[*, 5.2), 5.2-5.2.12, 5.3-5.3.9, 5.4-5.4.7, 5.5-5.5.6, 5.6-5.6.5, 5.7-5.7.3, 5.8-5.8.1

Correctif

5.2.13, 5.3.10, 5.4.8, 5.5.7, 5.6.6, 5.7.4, 5.8.2

Publication

10/11/2021

CVE-2021-39201 Élevée · 7,6
WordPress

WordPress Core 5.4 – 5.8 – Authenticated Stored Cross-Site Scripting

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor.…

Versions affectées

[5.4, 5.4.7), [5.5, 5.5.6), [5.6, 5.6.5), [5.7, 5.7.3), [5.8, 5.8.1)

Correctif

5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1

Publication

09/09/2021

CVE-2021-39200 Moyenne · 5,3
WordPress

WordPress Core 5.4 – 5.8 – Sensitive Information Disclosure

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include…

Versions affectées

[5.4, 5.4.7), [5.5, 5.5.6), [5.6, 5.6.5), [5.7, 5.7.3), [5.8, 5.8.1)

Correctif

5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1

Publication

09/09/2021

CVE-2020-8203 Moyenne · 6,1
WordPress

WordPress Core < 5.8.1 – LoDash Update

WordPress Core is vulnerable to prototype pollution in various versions less than 5.8.1 due to a vulnerability in the LoDash component which is identified as CVE-2020-8203.

Versions affectées

[5.4, 5.4.7), [5.5, 5.5.6), [5.6, 5.6.5), [5.7, 5.7.3), [5.8, 5.8.1)

Correctif

5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1

Publication

09/09/2021

CVE-2021-29450 Moyenne · 6,5
WordPress

WordPress Core < 5.7.1 – Sensitive Information Disclosure

Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress…

Versions affectées

[4.7, 4.7.20), [4.8, 4.8.16), [4.9, 4.9.17), [5.0, 5.0.12), [5.1, 5.1.9), [5.2, 5.2.10), [5.3, 5.3.7), [5.4, 5.4.5), [5.5, 5.5.4), [5.6, 5.6.3), [5.7, 5.7.1)

Correctif

4.7.20, 4.8.16, 4.9.17, 5.0.12, 5.1.9, 5.2.10, 5.3.7, 5.4.5, 5.5.4, 5.6.3, 5.7.1

Publication

15/04/2021

CVE-2021-29447 Élevée · 7,1
WordPress

WordPress Core < 5.7.1 – XXE Injection

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using…

Versions affectées

[4.7, 4.7.20), [4.8, 4.8.16), [4.9, 4.9.17), [5.0, 5.0.12), [5.1, 5.1.9), [5.2, 5.2.10), [5.3, 5.3.7), [5.4, 5.4.5), [5.5, 5.5.4), [5.6, 5.6.3), [5.7, 5.7.1)

Correctif

4.7.20, 4.8.16, 4.9.17, 5.0.12, 5.1.9, 5.2.10, 5.3.7, 5.4.5, 5.5.4, 5.6.3, 5.7.1

Publication

15/04/2021

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités