Répertoire de sécurité WordPress
Vulnérabilités du cœur WordPress, page 3
Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 3 de l’annuaire.
WordPress Core
Failles et CVE du cœur WordPress
WordPress Core < 6.0.3 – Shared User Instance Weakness
WordPress Core in versions up to 6.0.3 had a weakness in how Share User Instances were handled. This fix appears to have been necessary to safely use the wp_set_current_user( 0 ); method to patch the previously mentioned XSS…
*-3.6.1, 3.7-3.7.39, 3.8-3.8.39, 3.9-3.9.37, 4.0-4.0.36, 4.1-4.1.36, 4.2-4.2.33, 4.3-4.3.29, 4.4-4.4.28, 4.5-4.5.27, 4.6-4.6.24, 4.7-4.7.24, 4.8-4.8.20, 4.9-4.9.21, 5.0-5.0.17, 5.1-5.1.14, 5.2-5.2.16, 5.3-5.3.13, 5.4-5.4.11, 5.5-5.5.10, 5.6-5.6.9, 5.7-5.7.7, 5.8-5.8.5, 5.9-5.9.4, 6.0-6.0.2
3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3
18/10/2022
WordPress Core – All known versions – Unauthenticated Blind Server Side Request Forgery
WordPress Core, in all known versions is vulnerable to blind Server-Side Request Forgery in its pingback feature. This is due to a Time-of-Check-Time-of-Use (TOC-TOU) race condition between validation checks and HTTP requests that makes it possible for URLs…
*
Non indiqué
06/09/2022
WordPress Core < 6.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function
WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it…
*-3.6.1, 3.7-3.7.38, 3.8-3.8.38, 3.9-3.9.36, 4.0-4.0.35, 4.1-4.1.35, 4.2-4.2.32, 4.3-4.3.28, 4.4-4.4.27, 4.5-4.5.26, 4.6-4.6.23, 4.7-4.7.23, 4.8-4.8.19, 4.9-4.9.20, 5.0-5.0.16, 5.1-5.1.13, 5.2-5.2.15, 5.3-5.3.12, 5.4-5.4.10, 5.5-5.5.9, 5.6-5.6.8, 5.7-5.7.6, 5.8-5.8.4, 5.9-5.9.3, 6.0-6.0.1
3.7.39, 3.8.39, 3.9.37, 4.0.36, 4.1.36, 4.2.33, 4.3.29, 4.4.28, 4.5.27, 4.6.24, 4.7.24, 4.8.20, 4.9.21, 5.0.17, 5.1.14, 5.2.16, 5.3.13, 5.4.11, 5.5.10, 5.6.9, 5.7.7, 5.8.5, 5.9.4, 6.0.2
30/08/2022
WordPress Core < 6.0.2 – Stored Cross-Site Scripting via Plugin Deactivation and Deletion Errors
WordPress Core, in versions up to 6.0.2, is vulnerable to Stored Cross-Site Scripting that can be exploited when malicious content is injected into plugin code that triggers when an error occurs during plugin de-activation or during deletion. This…
*-3.6.1, 3.7-3.7.38, 3.8-3.8.38, 3.9-3.9.36, 4.0-4.0.35, 4.1-4.1.35, 4.2-4.2.32, 4.3-4.3.28, 4.4-4.4.27, 4.5-4.5.26, 4.6-4.6.23, 4.7-4.7.23, 4.8-4.8.19, 4.9-4.9.20, 5.0-5.0.16, 5.1-5.1.13, 5.2-5.2.15, 5.3-5.3.12, 5.4-5.4.10, 5.5-5.5.9, 5.6-5.6.8, 5.7-5.7.6, 5.8-5.8.4, 5.9-5.9.3, 6.0-6.0.1
3.7.39, 3.8.39, 3.9.37, 4.0.36, 4.1.36, 4.2.33, 4.3.29, 4.4.28, 4.5.27, 4.6.24, 4.7.24, 4.8.20, 4.9.21, 5.0.17, 5.1.14, 5.2.16, 5.3.13, 5.4.11, 5.5.10, 5.6.9, 5.7.7, 5.8.5, 5.9.4, 6.0.2
30/08/2022
WordPress Core < 6.0.2 – Authenticated SQL Injection
WordPress Core, in versions up to 6.0.2, is vulnerable to SQL Injection that can be exploited by authenticated users via the LIMIT parameter passed through the get_bookmarks function. This can be exploited on default WordPress installations by users…
*-3.6.1, 3.7-3.7.38, 3.8-3.8.38, 3.9-3.9.36, 4.0-4.0.35, 4.1-4.1.35, 4.2-4.2.32, 4.3-4.3.28, 4.4-4.4.27, 4.5-4.5.26, 4.6-4.6.23, 4.7-4.7.23, 4.8-4.8.19, 4.9-4.9.20, 5.0-5.0.16, 5.1-5.1.13, 5.2-5.2.15, 5.3-5.3.12, 5.4-5.4.10, 5.5-5.5.9, 5.6-5.6.8, 5.7-5.7.6, 5.8-5.8.4, 5.9-5.9.3, 6.0-6.0.1
3.7.39, 3.8.39, 3.9.37, 4.0.36, 4.1.36, 4.2.33, 4.3.29, 4.4.28, 4.5.27, 4.6.24, 4.7.24, 4.8.20, 4.9.21, 5.0.17, 5.1.14, 5.2.16, 5.3.13, 5.4.11, 5.5.10, 5.6.9, 5.7.7, 5.8.5, 5.9.4, 6.0.2
30/08/2022
WordPress Core < 5.9.1 – jQuery Prototype Pollution
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.
[*, 3.7), 3.7-3.7.37, 3.8-3.8.37, 3.9-3.9.35, 4.0-4.0.34, 4.1-4.1.34, 4.2-4.2.31, 4.3-4.3.27, 4.4-4.4.26, 4.5-4.5.25, 4.6-4.6.22, 4.7-4.7.22, 4.8-4.8.18, 4.9-4.9.19, 5.0-5.0.15, 5.1-5.1.12, 5.2-5.2.14, 5.3-5.3.11, 5.4-5.4.9, 5.5-5.5.8, 5.6-5.6.7, 5.7-5.7.5, 5.8-5.8.3, 5.9-5.9.1
3.7.38, 3.8.38, 3.9.36, 4.0.35, 4.1.35, 4.2.32, 4.3.28, 4.4.27, 4.5.26, 4.6.23, 4.7.23, 4.8.19, 4.9.20, 5.0.16, 5.1.13, 5.2.15, 5.3.12, 5.4.10, 5.5.9, 5.6.8, 5.7.6, 5.8.4, 5.9.2
11/03/2022
WordPress Core < 5.9.2 & Gutenberg < 12.7.2 – Prototype Pollution via Block Editor
WordPress Core in various versions < 5.9.2 and Gutenberg versions less than 12.7.2 are vulnerable to prototype pollution via the block editor which could make injecting malicious web scripts possible in some cases.
[*, 3.7), 3.7-3.7.37, 3.8-3.8.37, 3.9-3.9.35, 4.0-4.0.34, 4.1-4.1.34, 4.2-4.2.31, 4.3-4.3.27, 4.4-4.4.26, 4.5-4.5.25, 4.6-4.6.22, 4.7-4.7.22, 4.8-4.8.18, 4.9-4.9.19, 5.0-5.0.15, 5.1-5.1.12, 5.2-5.2.14, 5.3-5.3.11, 5.4-5.4.9, 5.5-5.5.8, 5.6-5.6.7, 5.7-5.7.5, 5.8-5.8.3, 5.9-5.9.1
3.7.38, 3.8.38, 3.9.36, 4.0.35, 4.1.35, 4.2.32, 4.3.28, 4.4.27, 4.5.26, 4.6.23, 4.7.23, 4.8.19, 4.9.20, 5.0.16, 5.1.13, 5.2.15, 5.3.12, 5.4.10, 5.5.9, 5.6.8, 5.7.6, 5.8.4, 5.9.2
11/03/2022
WordPress Core 5.9 – 5.9.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Core in versions 5.9 – 5.9.1 is vulnerable to Contributor+ stored Cross-Site Scripting via the double JSON encoded payloads set in the 'isGlobalStylesUserThemeJSON' parameter which is updatable via the post editor.
[5.9, 5.9.2)
5.9.2
11/03/2022
WordPress Core < 5.8.3 – Authenticated (Author+) Stored Cross Site Scripting
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged…
[3.7, 3.7.37), [3.8, 3.8.37), [3.9, 3.9.35), [4.0, 4.0.34), [4.1, 4.1.34), [4.2, 4.2.31), [4.3, 4.3.27), [4.4, 4.4.26), [4.5, 4.5.25), [4.6, 4.6.22), [4.7, 4.7.22), [4.8, 4.8.18), [4.9, 4.9.19), [5.0, 5.0.15), [5.1, 5.1.12), [5.2, 5.2.14), [5.3, 5.3.11), [5.4, 5.4.9), [5.5, 5.5.8), [5.6, 5.6.7), [5.7, 5.7.5), [5.8, 5.8.3)
3.7.37, 3.8.37, 3.9.35, 4.0.34, 4.1.34, 4.2.31, 4.3.27, 4.4.26, 4.5.25, 4.6.22, 4.7.22, 4.8.18, 4.9.19, 5.0.15, 5.1.12, 5.2.14, 5.3.11, 5.4.9, 5.5.8, 5.6.7, 5.7.5, 5.8.3
06/01/2022
WordPress Core < 5.8.3 – Super Admin Multi-Site Installation Object Injection
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has…
[3.7, 3.7.37), [3.8, 3.8.37), [3.9, 3.9.35), [4.0, 4.0.34), [4.1, 4.1.34), [4.2, 4.2.31), [4.3, 4.3.27), [4.4, 4.4.26), [4.5, 4.5.25), [4.6, 4.6.22), [4.7, 4.7.22), [4.8, 4.8.18), [4.9, 4.9.19), [5.0, 5.0.15), [5.1, 5.1.12), [5.2, 5.2.14), [5.3, 5.3.11), [5.4, 5.4.9), [5.5, 5.5.8), [5.6, 5.6.7), [5.7, 5.7.5), [5.8, 5.8.3)
3.7.37, 3.8.37, 3.9.35, 4.0.34, 4.1.34, 4.2.31, 4.3.27, 4.4.26, 4.5.25, 4.6.22, 4.7.22, 4.8.18, 4.9.19, 5.0.15, 5.1.12, 5.2.14, 5.3.11, 5.4.9, 5.5.8, 5.6.7, 5.7.5, 5.8.3
06/01/2022
WordPress Core < 5.8.3 – SQL Injection via WP_Meta_Query
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed.…
[4.1, 4.1.34), [4.2, 4.2.31), [4.3, 4.3.27), [4.4, 4.4.26), [4.5, 4.5.25), [4.6, 4.6.22), [4.7, 4.7.22), [4.8, 4.8.18), [4.9, 4.9.19), [5.0, 5.0.15), [5.1, 5.1.12), [5.2, 5.2.14), [5.3, 5.3.11), [5.4, 5.4.9), [5.5, 5.5.8), [5.6, 5.6.7), [5.7, 5.7.5), [5.8, 5.8.3)
4.1.34, 4.2.31, 4.3.27, 4.4.26, 4.5.25, 4.6.22, 4.7.22, 4.8.18, 4.9.19, 5.0.15, 5.1.12, 5.2.14, 5.3.11, 5.4.9, 5.5.8, 5.6.7, 5.7.5, 5.8.3
06/01/2022
WordPress Core < 5.8 – Dependency Confusion
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies…
*-5.7.5
5.8
25/11/2021
WordPress Core < 5.8.2 – ca-bundle.crt contains expired certificate DST Root CA X3
WordPress Core in various versions less than version 5.8.2 contained an expired DST Root CA X3 certificate. There is no significant security risk to most WordPress users.
[*, 5.2), 5.2-5.2.12, 5.3-5.3.9, 5.4-5.4.7, 5.5-5.5.6, 5.6-5.6.5, 5.7-5.7.3, 5.8-5.8.1
5.2.13, 5.3.10, 5.4.8, 5.5.7, 5.6.6, 5.7.4, 5.8.2
10/11/2021
WordPress Core 5.8 beta – Stored Cross-Site Scripting in Custom HTML Block
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input…
5.8 beta 1 – 5.8 beta 2
5.8
09/09/2021
WordPress Core 5.8 beta – Block Editor Authorization Bypass
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in…
5.8 beta 1
5.8
09/09/2021
WordPress Core 5.4 – 5.8 – Authenticated Stored Cross-Site Scripting
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor.…
[5.4, 5.4.7), [5.5, 5.5.6), [5.6, 5.6.5), [5.7, 5.7.3), [5.8, 5.8.1)
5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1
09/09/2021
WordPress Core 5.4 – 5.8 – Sensitive Information Disclosure
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include…
[5.4, 5.4.7), [5.5, 5.5.6), [5.6, 5.6.5), [5.7, 5.7.3), [5.8, 5.8.1)
5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1
09/09/2021
WordPress Core < 5.8.1 – LoDash Update
WordPress Core is vulnerable to prototype pollution in various versions less than 5.8.1 due to a vulnerability in the LoDash component which is identified as CVE-2020-8203.
[5.4, 5.4.7), [5.5, 5.5.6), [5.6, 5.6.5), [5.7, 5.7.3), [5.8, 5.8.1)
5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1
09/09/2021
WordPress Core < 5.7.1 – Sensitive Information Disclosure
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress…
[4.7, 4.7.20), [4.8, 4.8.16), [4.9, 4.9.17), [5.0, 5.0.12), [5.1, 5.1.9), [5.2, 5.2.10), [5.3, 5.3.7), [5.4, 5.4.5), [5.5, 5.5.4), [5.6, 5.6.3), [5.7, 5.7.1)
4.7.20, 4.8.16, 4.9.17, 5.0.12, 5.1.9, 5.2.10, 5.3.7, 5.4.5, 5.5.4, 5.6.3, 5.7.1
15/04/2021
WordPress Core < 5.7.1 – XXE Injection
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using…
[4.7, 4.7.20), [4.8, 4.8.16), [4.9, 4.9.17), [5.0, 5.0.12), [5.1, 5.1.9), [5.2, 5.2.10), [5.3, 5.3.7), [5.4, 5.4.5), [5.5, 5.5.4), [5.6, 5.6.3), [5.7, 5.7.1)
4.7.20, 4.8.16, 4.9.17, 5.0.12, 5.1.9, 5.2.10, 5.3.7, 5.4.5, 5.5.4, 5.6.3, 5.7.1
15/04/2021
Comprendre les données
Comment utiliser cet annuaire de vulnérabilités ?
Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.
Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.