Répertoire de sécurité WordPress
Vulnérabilités du cœur WordPress, page 4
Consultez 389 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 4 de l’annuaire.
WordPress Core
Failles et CVE du cœur WordPress
WordPress Core < 5.8 – Dependency Confusion
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies…
*-5.7.5
5.8
25/11/2021
WordPress Core < 5.8.2 – ca-bundle.crt contains expired certificate DST Root CA X3
WordPress Core in various versions less than version 5.8.2 contained an expired DST Root CA X3 certificate. There is no significant security risk to most WordPress users.
[*, 5.2), 5.2-5.2.12, 5.3-5.3.9, 5.4-5.4.7, 5.5-5.5.6, 5.6-5.6.5, 5.7-5.7.3, 5.8-5.8.1
5.2.13, 5.3.10, 5.4.8, 5.5.7, 5.6.6, 5.7.4, 5.8.2
10/11/2021
WordPress Core 5.8 beta – Stored Cross-Site Scripting in Custom HTML Block
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input…
5.8 beta 1 – 5.8 beta 2
5.8
09/09/2021
WordPress Core 5.8 beta – Block Editor Authorization Bypass
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in…
5.8 beta 1
5.8
09/09/2021
WordPress Core 5.4 – 5.8 – Authenticated Stored Cross-Site Scripting
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor.…
[5.4, 5.4.7), [5.5, 5.5.6), [5.6, 5.6.5), [5.7, 5.7.3), [5.8, 5.8.1)
5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1
09/09/2021
WordPress Core 5.4 – 5.8 – Sensitive Information Disclosure
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include…
[5.4, 5.4.7), [5.5, 5.5.6), [5.6, 5.6.5), [5.7, 5.7.3), [5.8, 5.8.1)
5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1
09/09/2021
WordPress Core < 5.8.1 – LoDash Update
WordPress Core is vulnerable to prototype pollution in various versions less than 5.8.1 due to a vulnerability in the LoDash component which is identified as CVE-2020-8203.
[5.4, 5.4.7), [5.5, 5.5.6), [5.6, 5.6.5), [5.7, 5.7.3), [5.8, 5.8.1)
5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1
09/09/2021
WordPress Core < 5.7.1 – Sensitive Information Disclosure
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress…
[4.7, 4.7.20), [4.8, 4.8.16), [4.9, 4.9.17), [5.0, 5.0.12), [5.1, 5.1.9), [5.2, 5.2.10), [5.3, 5.3.7), [5.4, 5.4.5), [5.5, 5.5.4), [5.6, 5.6.3), [5.7, 5.7.1)
4.7.20, 4.8.16, 4.9.17, 5.0.12, 5.1.9, 5.2.10, 5.3.7, 5.4.5, 5.5.4, 5.6.3, 5.7.1
15/04/2021
WordPress Core < 5.7.1 – XXE Injection
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using…
[4.7, 4.7.20), [4.8, 4.8.16), [4.9, 4.9.17), [5.0, 5.0.12), [5.1, 5.1.9), [5.2, 5.2.10), [5.3, 5.3.7), [5.4, 5.4.5), [5.5, 5.5.4), [5.6, 5.6.3), [5.7, 5.7.1)
4.7.20, 4.8.16, 4.9.17, 5.0.12, 5.1.9, 5.2.10, 5.3.7, 5.4.5, 5.5.4, 5.6.3, 5.7.1
15/04/2021
WordPress Core < 5.8.3 – SQL Injection via WP_Query
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that…
[3.7, 3.7.37), [3.8, 3.8.37), [3.9, 3.9.35), [4.0, 4.0.34), [4.1, 4.1.34), [4.2, 4.2.31), [4.3, 4.3.27), [4.4, 4.4.26), [4.5, 4.5.25), [4.6, 4.6.22), [4.7, 4.7.22), [4.8, 4.8.18), [4.9, 4.9.19), [5.0, 5.0.15), [5.1, 5.1.12), [5.2, 5.2.14), [5.3, 5.3.11), [5.4, 5.4.9), [5.5, 5.5.8), [5.6, 5.6.7), [5.7, 5.7.5), [5.8, 5.8.3)
3.7.37, 3.8.37, 3.9.35, 4.0.34, 4.1.34, 4.2.31, 4.3.27, 4.4.26, 4.5.25, 4.6.22, 4.7.22, 4.8.18, 4.9.19, 5.0.15, 5.1.12, 5.2.14, 5.3.11, 5.4.9, 5.5.8, 5.6.7, 5.7.5, 5.8.3
06/01/2021
WordPress Core < 5.5.2 – Privilege Escalation via XML-RPC
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
[*, 3.7), 3.7-3.7.34, 3.8-3.8.34, 3.9-3.9.32, 4.0-4.0.31, 4.1-4.1.31, 4.2-4.2.28, 4.3-4.3.24, 4.4-4.4.23, 4.5-4.5.22, 4.6-4.6.19, 4.7-4.7.18, 4.8-4.8.14, 4.9-4.9.15, 5.0-5.0.10, 5.1-5.1.6, 5.2-5.2.7, 5.3-5.3.4, 5.4-5.4.2, 5.5-5.5.1
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.7, 5.2.8, 5.3.5, 5.4.3, 5.5.2
29/10/2020
WordPress Core < 5.5.2 – Spam Embed on Multisite Installations
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
[*, 3.7), 3.7-3.7.34, 3.8-3.8.34, 3.9-3.9.32, 4.0-4.0.31, 4.1-4.1.31, 4.2-4.2.28, 4.3-4.3.24, 4.4-4.4.23, 4.5-4.5.22, 4.6-4.6.19, 4.7-4.7.18, 4.8-4.8.14, 4.9-4.9.15, 5.0-5.0.10, 5.1-5.1.6, 5.2-5.2.7, 5.3-5.3.4, 5.4-5.4.2, 5.5-5.5.1
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.7, 5.2.8, 5.3.5, 5.4.3, 5.5.2
29/10/2020
WordPress Core < 5.5.2 – Arbitrary File Deletion
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
[*, 3.7), 3.7-3.7.34, 3.8-3.8.34, 3.9-3.9.32, 4.0-4.0.31, 4.1-4.1.31, 4.2-4.2.28, 4.3-4.3.24, 4.4-4.4.23, 4.5-4.5.22, 4.6-4.6.19, 4.7-4.7.18, 4.8-4.8.14, 4.9-4.9.15, 5.0-5.0.10, 5.1-5.1.6, 5.2-5.2.7, 5.3-5.3.4, 5.4-5.4.2, 5.5-5.5.1
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.7, 5.2.8, 5.3.5, 5.4.3, 5.5.2
29/10/2020
WordPress Core < 5.5.2 – Misconfiguration That Allows Trigger of New Installation
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the…
[*, 3.7), 3.7-3.7.34, 3.8-3.8.34, 3.9-3.9.32, 4.0-4.0.31, 4.1-4.1.31, 4.2-4.2.28, 4.3-4.3.24, 4.4-4.4.23, 4.5-4.5.22, 4.6-4.6.19, 4.7-4.7.18, 4.8-4.8.14, 4.9-4.9.15, 5.0-5.0.10, 5.1-5.1.6, 5.2-5.2.7, 5.3-5.3.4, 5.4-5.4.2, 5.5-5.5.1
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.7, 5.2.8, 5.3.5, 5.4.3, 5.5.2
29/10/2020
WordPress Core < 5.5.2 – Stored Cross-Site Scripting via post slugs
WordPress before 5.5.2 allows stored XSS via post slugs.
[*, 3.7), 3.7-3.7.34, 3.8-3.8.34, 3.9-3.9.32, 4.0-4.0.31, 4.1-4.1.31, 4.2-4.2.28, 4.3-4.3.24, 4.4-4.4.23, 4.5-4.5.22, 4.6-4.6.19, 4.7-4.7.18, 4.8-4.8.14, 4.9-4.9.15, 5.0-5.0.10, 5.1-5.1.6, 5.2-5.2.7, 5.3-5.3.4, 5.4-5.4.2, 5.5-5.5.1
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.7, 5.2.8, 5.3.5, 5.4.3, 5.5.2
29/10/2020
WordPress Core < 5.5.2 – Cross-Site Request Forgery to Theme Image Change
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
[*, 3.7), 3.7-3.7.34, 3.8-3.8.34, 3.9-3.9.32, 4.0-4.0.31, 4.1-4.1.31, 4.2-4.2.28, 4.3-4.3.24, 4.4-4.4.23, 4.5-4.5.22, 4.6-4.6.19, 4.7-4.7.18, 4.8-4.8.14, 4.9-4.9.15, 5.0-5.0.10, 5.1-5.1.6, 5.2-5.2.7, 5.3-5.3.4, 5.4-5.4.2, 5.5-5.5.1
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.7, 5.2.8, 5.3.5, 5.4.3, 5.5.2
29/10/2020
WordPress Core < 5.5.3 – PHP Object Injection Gadget
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.
[*, 3.7), [3.7, 3.7.35), [3.8, 3.8.35), [3.9, 3.9.33), [4.0, 4.0.32), [4.1, 4.1.32), [4.2, 4.2.29), [4.3, 4.3.25), [4.4, 4.4.24), [4.5, 4.5.23), [4.6, 4.6.20), [4.7, 4.7.19), [4.8, 4.8.15), [4.9, 4.9.16), [5.0, 5.0.11), [5.1, 5.1.8), [5.2, 5.2.9), [5.3, 5.3.6), [5.4, 5.4.4), [5.5, 5.5.3)
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.8, 5.2.9, 5.3.6, 5.4.4, 5.5.3
29/10/2020
WordPress Core < 5.5.2 – Deserialization Gadget
WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
[*, 3.7), 3.7-3.7.34, 3.8-3.8.34, 3.9-3.9.32, 4.0-4.0.31, 4.1-4.1.31, 4.2-4.2.28, 4.3-4.3.24, 4.4-4.4.23, 4.5-4.5.22, 4.6-4.6.19, 4.7-4.7.18, 4.8-4.8.14, 4.9-4.9.15, 5.0-5.0.10, 5.1-5.1.6, 5.2-5.2.7, 5.3-5.3.4, 5.4-5.4.2, 5.5-5.5.1
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.7, 5.2.8, 5.3.5, 5.4.3, 5.5.2
29/10/2020
WordPress Core < 5.5.2 – Reflected Cross-Site Scripting via Global Variables
WordPress before 5.5.2 allows XSS associated with global variables.
[*, 3.7), 3.7-3.7.34, 3.8-3.8.34, 3.9-3.9.32, 4.0-4.0.31, 4.1-4.1.31, 4.2-4.2.28, 4.3-4.3.24, 4.4-4.4.23, 4.5-4.5.22, 4.6-4.6.19, 4.7-4.7.18, 4.8-4.8.14, 4.9-4.9.15, 5.0-5.0.10, 5.1-5.1.6, 5.2-5.2.7, 5.3-5.3.4, 5.4-5.4.2, 5.5-5.5.1
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.7, 5.2.8, 5.3.5, 5.4.3, 5.5.2
29/10/2020
WordPress Core < 5.5.2 – Privilege Escalation via XML-RPC
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
[*, 3.7), 3.7-3.7.34, 3.8-3.8.34, 3.9-3.9.32, 4.0-4.0.31, 4.1-4.1.31, 4.2-4.2.28, 4.3-4.3.24, 4.4-4.4.23, 4.5-4.5.22, 4.6-4.6.19, 4.7-4.7.18, 4.8-4.8.14, 4.9-4.9.15, 5.0-5.0.10, 5.1-5.1.6, 5.2-5.2.7, 5.3-5.3.4, 5.4-5.4.2, 5.5-5.5.1
3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.7, 5.2.8, 5.3.5, 5.4.3, 5.5.2
29/10/2020
Comprendre les données
Comment utiliser cet annuaire de vulnérabilités ?
Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.
Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.