Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 5

Consultez 389 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 5 de l’annuaire.

389Vulnérabilités
17Critiques
387Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

CVE-2020-4049 Faible · 2,4
WordPress

WordPress Core < 5.4.2 – Self-Cross Site Scripting via Theme Folder Name

In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to…

Versions affectées

[*, 3.7), 3.7-3.7.33, 3.8-3.8.33, 3.9-3.9.31, 4.0-4.0.30, 4.1-4.1.30, 4.2-4.2.27, 4.3-4.3.23, 4.4-4.4.22, 4.5-4.5.21, 4.6-4.6.18, 4.7-4.7.17, 4.8-4.8.13, 4.9-4.9.14, 5.0-5.0.9, 5.1-5.1.5, 5.2-5.2.6, 5.3-5.3.3

Correctif

3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2

Publication

10/06/2020

CVE-2020-4048 Moyenne · 5,7
WordPress

WordPress Core < 5.4.2 – Open Redirect

In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the…

Versions affectées

[*, 3.7), 3.7-3.7.33, 3.8-3.8.33, 3.9-3.9.31, 4.0-4.0.30, 4.1-4.1.30, 4.2-4.2.27, 4.3-4.3.23, 4.4-4.4.22, 4.5-4.5.21, 4.6-4.6.18, 4.7-4.7.17, 4.8-4.8.13, 4.9-4.9.14, 5.0-5.0.9, 5.1-5.1.5, 5.2-5.2.6, 5.3-5.3.3

Correctif

3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2

Publication

10/06/2020

CVE-2020-4050 Faible · 3,5
WordPress

WordPress Core < 5.4.2 – Arbitrary User Meta Update

In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can…

Versions affectées

[*, 3.7), 3.7-3.7.33, 3.8-3.8.33, 3.9-3.9.31, 4.0-4.0.30, 4.1-4.1.30, 4.2-4.2.27, 4.3-4.3.23, 4.4-4.4.22, 4.5-4.5.21, 4.6-4.6.18, 4.7-4.7.17, 4.8-4.8.13, 4.9-4.9.14, 5.0-5.0.9, 5.1-5.1.5, 5.2-5.2.6, 5.3-5.3.3

Correctif

3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2

Publication

10/06/2020

CVE-2020-25286 Moyenne · 5,3
WordPress

WordPress Core < 5.4.2 – Comment Disclosure

In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

Versions affectées

[*, 3.7), 3.7-3.7.33, 3.8-3.8.33, 3.9-3.9.31, 4.0-4.0.30, 4.1-4.1.30, 4.2-4.2.27, 4.3-4.3.23, 4.4-4.4.22, 4.5-4.5.21, 4.6-4.6.18, 4.7-4.7.17, 4.8-4.8.13, 4.9-4.9.14, 5.0-5.0.9, 5.1-5.1.5, 5.2-5.2.6, 5.3-5.3.3

Correctif

3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2

Publication

10/06/2020

CVE-2020-4046 Moyenne · 5,4
WordPress

WordPress Core < 5.4.2 – Authenticated Stored Cross-Site Scripting

In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher…

Versions affectées

[*, 3.7), 3.7-3.7.33, 3.8-3.8.33, 3.9-3.9.31, 4.0-4.0.30, 4.1-4.1.30, 4.2-4.2.27, 4.3-4.3.23, 4.4-4.4.22, 4.5-4.5.21, 4.6-4.6.18, 4.7-4.7.17, 4.8-4.8.13, 4.9-4.9.14, 5.0-5.0.9, 5.1-5.1.5, 5.2-5.2.6, 5.3-5.3.3

Correctif

3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2

Publication

10/06/2020

CVE-2020-4047 Moyenne · 6,8
WordPress

WordPress Core < 5.4.2 – Authenticated Stored Cross-Site Scripting

In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a…

Versions affectées

[*, 3.7), 3.7-3.7.33, 3.8-3.8.33, 3.9-3.9.31, 4.0-4.0.30, 4.1-4.1.30, 4.2-4.2.27, 4.3-4.3.23, 4.4-4.4.22, 4.5-4.5.21, 4.6-4.6.18, 4.7-4.7.17, 4.8-4.8.13, 4.9-4.9.14, 5.0-5.0.9, 5.1-5.1.5, 5.2-5.2.6, 5.3-5.3.3

Correctif

3.7.34, 3.8.34, 3.9.32, 4.0.31, 4.1.31, 4.2.28, 4.3.24, 4.4.23, 4.5.22, 4.6.19, 4.7.18, 4.8.14, 4.9.15, 5.0.10, 5.1.6, 5.2.7, 5.3.4, 5.4.2

Publication

10/06/2020

CVE-2020-11028 Moyenne · 5,8
WordPress

WordPress Core < 5.4.1 – Private Post Disclosure

In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affected versions via…

Versions affectées

[*, 3.7), 3.7-3.7.32, 3.8-3.8.32, 3.9-3.9.30, 4.0-4.0.29, 4.1-4.1.29, 4.2-4.2.26, 4.3-4.3.22, 4.4-4.4.21, 4.5-4.5.20, 4.6-4.6.17, 4.7-4.7.16, 4.8-4.8.12, 4.9-4.9.13, 5.0-5.0.8, 5.1-5.1.4, 5.2-5.2.5, 5.3-5.3.2, 5.4

Correctif

3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1

Publication

29/04/2020

CVE-2020-11025 Moyenne · 5,8
WordPress

WordPress Core < 5.4.1 – Authenticated Cross-Site Scripting via Customizer

In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the…

Versions affectées

[*, 3.7), 3.7-3.7.32, 3.8-3.8.32, 3.9-3.9.30, 4.0-4.0.29, 4.1-4.1.29, 4.2-4.2.26, 4.3-4.3.22, 4.4-4.4.21, 4.5-4.5.20, 4.6-4.6.17, 4.7-4.7.16, 4.8-4.8.12, 4.9-4.9.13, 5.0-5.0.8, 5.1-5.1.4, 5.2-5.2.5, 5.3-5.3.2, 5.4

Correctif

3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1

Publication

29/04/2020

CVE-2020-11029 Moyenne · 5,8
WordPress

WordPress Core < 5.4.1 – Reflected Cross Site Scripting

In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been patched in version 5.4.1, along with all the previously affected versions via a…

Versions affectées

[*, 3.7), 3.7-3.7.32, 3.8-3.8.32, 3.9-3.9.30, 4.0-4.0.29, 4.1-4.1.29, 4.2-4.2.26, 4.3-4.3.22, 4.4-4.4.21, 4.5-4.5.20, 4.6-4.6.17, 4.7-4.7.16, 4.8-4.8.12, 4.9-4.9.13, 5.0-5.0.8, 5.1-5.1.4, 5.2-5.2.5, 5.3-5.3.2, 5.4

Correctif

3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1

Publication

29/04/2020

CVE-2020-11027 Moyenne · 6,1
WordPress

WordPress Core < 5.4.1 – Password Reset Link Non-Expiration

In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful…

Versions affectées

[*, 3.7), 3.7-3.7.32, 3.8-3.8.32, 3.9-3.9.30, 4.0-4.0.29, 4.1-4.1.29, 4.2-4.2.26, 4.3-4.3.22, 4.4-4.4.21, 4.5-4.5.20, 4.6-4.6.17, 4.7-4.7.16, 4.8-4.8.12, 4.9-4.9.13, 5.0-5.0.8, 5.1-5.1.4, 5.2-5.2.5, 5.3-5.3.2, 5.4

Correctif

3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1

Publication

29/04/2020

CVE-2020-11030 Moyenne · 6,4
WordPress

WordPress Core < 5.4.1 – Cross-Site Scripting in the Block Editor

In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This…

Versions affectées

[*, 3.7), 3.7-3.7.32, 3.8-3.8.32, 3.9-3.9.30, 4.0-4.0.29, 4.1-4.1.29, 4.2-4.2.26, 4.3-4.3.22, 4.4-4.4.21, 4.5-4.5.20, 4.6-4.6.17, 4.7-4.7.16, 4.8-4.8.12, 4.9-4.9.13, 5.0-5.0.8, 5.1-5.1.4, 5.2-5.2.5, 5.3-5.3.2, 5.4

Correctif

3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1

Publication

29/04/2020

CVE-2020-11026 Moyenne · 6,4
WordPress

WordPress Core < 5.4.1 – Authenticated (Author+) Cross-Site Scripting via File Uploads

In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has…

Versions affectées

[*, 3.7), 3.7-3.7.32, 3.8-3.8.32, 3.9-3.9.30, 4.0-4.0.29, 4.1-4.1.29, 4.2-4.2.26, 4.3-4.3.22, 4.4-4.4.21, 4.5-4.5.20, 4.6-4.6.17, 4.7-4.7.16, 4.8-4.8.12, 4.9-4.9.13, 5.0-5.0.8, 5.1-5.1.4, 5.2-5.2.5, 5.3-5.3.2, 5.4

Correctif

3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1

Publication

29/04/2020

CVE-2019-20042 Moyenne · 6,4
WordPress

WordPress Core < 5.3.1 – Authenticated Stored Cross-Site Scripting

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous…

Versions affectées

[*, 3.7), 3.7-3.7.31, 3.8-3.8.31, 3.9-3.9.29, 4.0-4.0.28, 4.1-4.1.28, 4.2-4.2.25, 4.3-4.3.21, 4.4-4.4.20, 4.5-4.5.19, 4.6-4.6.16, 4.7-4.7.15, 4.8-4.8.11, 4.9-4.9.12, 5.0-5.0.7, 5.1-5.1.3, 5.2-5.2.4, 5.3

Correctif

3.7.32, 3.8.32, 3.9.30, 4.0.29, 4.1.29, 4.2.26, 4.3.22, 4.4.21, 4.5.20, 4.6.17, 4.7.16, 4.8.12, 4.9.13, 5.0.8, 5.1.4, 5.2.5, 5.3.1

Publication

13/12/2019

CVE-2019-16780 Moyenne · 5,8
WordPress

WordPress Core < 5.3.1 – Stored Cross-Site Scripting via Block Editor

WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the…

Versions affectées

[*, 3.7), 3.7-3.7.31, 3.8-3.8.31, 3.9-3.9.29, 4.0-4.0.28, 4.1-4.1.28, 4.2-4.2.25, 4.3-4.3.21, 4.4-4.4.20, 4.5-4.5.19, 4.6-4.6.16, 4.7-4.7.15, 4.8-4.8.11, 4.9-4.9.12, 5.0-5.0.7, 5.1-5.1.3, 5.2-5.2.4, 5.3

Correctif

3.7.32, 3.8.32, 3.9.30, 4.0.29, 4.1.29, 4.2.26, 4.3.22, 4.4.21, 4.5.20, 4.6.17, 4.7.16, 4.8.12, 4.9.13, 5.0.8, 5.1.4, 5.2.5, 5.3.1

Publication

13/12/2019

CVE-2019-20041 Moyenne · 6,4
WordPress

WordPress Core < 5.3.1 – Authenticated Stored Cross-Site Scripting

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript&colon; substring.

Versions affectées

[*, 3.7), 3.7-3.7.31, 3.8-3.8.31, 3.9-3.9.29, 4.0-4.0.28, 4.1-4.1.28, 4.2-4.2.25, 4.3-4.3.21, 4.4-4.4.20, 4.5-4.5.19, 4.6-4.6.16, 4.7-4.7.15, 4.8-4.8.11, 4.9-4.9.12, 5.0-5.0.7, 5.1-5.1.3, 5.2-5.2.4, 5.3

Correctif

3.7.32, 3.8.32, 3.9.30, 4.0.29, 4.1.29, 4.2.26, 4.3.22, 4.4.21, 4.5.20, 4.6.17, 4.7.16, 4.8.12, 4.9.13, 5.0.8, 5.1.4, 5.2.5, 5.3.1

Publication

13/12/2019

CVE-2019-16781 Moyenne · 5,8
WordPress

WordPress Core < 5.3.1 – Authenticated Stored Cross-Site Scripting

In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor…

Versions affectées

[*, 3.7), 3.7-3.7.31, 3.8-3.8.31, 3.9-3.9.29, 4.0-4.0.28, 4.1-4.1.28, 4.2-4.2.25, 4.3-4.3.21, 4.4-4.4.20, 4.5-4.5.19, 4.6-4.6.16, 4.7-4.7.15, 4.8-4.8.11, 4.9-4.9.12, 5.0-5.0.7, 5.1-5.1.3, 5.2-5.2.4

Correctif

3.7.32, 3.8.32, 3.9.30, 4.0.29, 4.1.29, 4.2.26, 4.3.22, 4.4.21, 4.5.20, 4.6.17, 4.7.16, 4.8.12, 4.9.13, 5.0.8, 5.1.4, 5.2.5, 5.3.1

Publication

13/12/2019

CVE-2019-20043 Moyenne · 4,3
WordPress

WordPress Core < 5.3.1 – Authorization Bypass

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role…

Versions affectées

[*, 3.7), 3.7-3.7.31, 3.8-3.8.31, 3.9-3.9.29, 4.0-4.0.28, 4.1-4.1.28, 4.2-4.2.25, 4.3-4.3.21, 4.4-4.4.20, 4.5-4.5.19, 4.6-4.6.16, 4.7-4.7.15, 4.8-4.8.11, 4.9-4.9.12, 5.0-5.0.7, 5.1-5.1.3, 5.2-5.2.4, 5.3

Correctif

3.7.32, 3.8.32, 3.9.30, 4.0.29, 4.1.29, 4.2.26, 4.3.22, 4.4.21, 4.5.20, 4.6.17, 4.7.16, 4.8.12, 4.9.13, 5.0.8, 5.1.4, 5.2.5, 5.3.1

Publication

01/12/2019

CVE-2019-17672 Moyenne · 6,4
WordPress

WordPress Core < 5.2.4 – Authenticated Stored Cross-Site Scripting

WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.

Versions affectées

[*, 3.7), 3.7-3.7.30, 3.8-3.8.30, 3.9-3.9.28, 4.0-4.0.27, 4.1-4.1.27, 4.2-4.2.24, 4.3-4.3.20, 4.4-4.4.19, 4.5-4.5.18, 4.6-4.6.15, 4.7-4.7.13, 4.7-4.7.14, 4.8-4.8.10, 4.9-4.9.11, 5.0-5.0.6, 5.1-5.1.2, 5.2-5.2.3

Correctif

3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.15, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4

Publication

14/10/2019

CVE-2019-17670 Moyenne · 5,4
WordPress

WordPress Core < 5.2.4 – Server Side Request Forgery #2

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.

Versions affectées

[*, 3.7), 3.7-3.7.30, 3.8-3.8.30, 3.9-3.9.28, 4.0-4.0.27, 4.1-4.1.27, 4.2-4.2.24, 4.3-4.3.20, 4.4-4.4.19, 4.5-4.5.18, 4.6-4.6.15, 4.7-4.7.13, 4.8-4.8.10, 4.9-4.9.11, 5.0-5.0.6, 5.1-5.1.2, 5.2-5.2.3

Correctif

3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.14, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4

Publication

14/10/2019

CVE-2019-17669 Moyenne · 5,4
WordPress

WordPress Core < 5.2.4 – Server Side Request Forgery

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.

Versions affectées

[*, 3.7), 3.7-3.7.30, 3.8-3.8.30, 3.9-3.9.28, 4.0-4.0.27, 4.1-4.1.27, 4.2-4.2.24, 4.3-4.3.20, 4.4-4.4.19, 4.5-4.5.18, 4.6-4.6.15, 4.7-4.7.13, 4.8-4.8.10, 4.9-4.9.11, 5.0-5.0.6, 5.1-5.1.2, 5.2-5.2.3

Correctif

3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.14, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4

Publication

14/10/2019

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités