Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 5

Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 5 de l’annuaire.

380Vulnérabilités
17Critiques
378Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

CVE-2020-11027 Moyenne · 6,1
WordPress

WordPress Core < 5.4.1 – Password Reset Link Non-Expiration

In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful…

Versions affectées

[*, 3.7), 3.7-3.7.32, 3.8-3.8.32, 3.9-3.9.30, 4.0-4.0.29, 4.1-4.1.29, 4.2-4.2.26, 4.3-4.3.22, 4.4-4.4.21, 4.5-4.5.20, 4.6-4.6.17, 4.7-4.7.16, 4.8-4.8.12, 4.9-4.9.13, 5.0-5.0.8, 5.1-5.1.4, 5.2-5.2.5, 5.3-5.3.2, 5.4

Correctif

3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1

Publication

29/04/2020

CVE-2020-11030 Moyenne · 6,4
WordPress

WordPress Core < 5.4.1 – Cross-Site Scripting in the Block Editor

In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authenticated user with the ability to add content. This…

Versions affectées

[*, 3.7), 3.7-3.7.32, 3.8-3.8.32, 3.9-3.9.30, 4.0-4.0.29, 4.1-4.1.29, 4.2-4.2.26, 4.3-4.3.22, 4.4-4.4.21, 4.5-4.5.20, 4.6-4.6.17, 4.7-4.7.16, 4.8-4.8.12, 4.9-4.9.13, 5.0-5.0.8, 5.1-5.1.4, 5.2-5.2.5, 5.3-5.3.2, 5.4

Correctif

3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1

Publication

29/04/2020

CVE-2020-11026 Moyenne · 6,4
WordPress

WordPress Core < 5.4.1 – Authenticated (Author+) Cross-Site Scripting via File Uploads

In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has…

Versions affectées

[*, 3.7), 3.7-3.7.32, 3.8-3.8.32, 3.9-3.9.30, 4.0-4.0.29, 4.1-4.1.29, 4.2-4.2.26, 4.3-4.3.22, 4.4-4.4.21, 4.5-4.5.20, 4.6-4.6.17, 4.7-4.7.16, 4.8-4.8.12, 4.9-4.9.13, 5.0-5.0.8, 5.1-5.1.4, 5.2-5.2.5, 5.3-5.3.2, 5.4

Correctif

3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1

Publication

29/04/2020

CVE-2019-20042 Moyenne · 6,4
WordPress

WordPress Core < 5.3.1 – Authenticated Stored Cross-Site Scripting

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous…

Versions affectées

[*, 3.7), 3.7-3.7.31, 3.8-3.8.31, 3.9-3.9.29, 4.0-4.0.28, 4.1-4.1.28, 4.2-4.2.25, 4.3-4.3.21, 4.4-4.4.20, 4.5-4.5.19, 4.6-4.6.16, 4.7-4.7.15, 4.8-4.8.11, 4.9-4.9.12, 5.0-5.0.7, 5.1-5.1.3, 5.2-5.2.4, 5.3

Correctif

3.7.32, 3.8.32, 3.9.30, 4.0.29, 4.1.29, 4.2.26, 4.3.22, 4.4.21, 4.5.20, 4.6.17, 4.7.16, 4.8.12, 4.9.13, 5.0.8, 5.1.4, 5.2.5, 5.3.1

Publication

13/12/2019

CVE-2019-16780 Moyenne · 5,8
WordPress

WordPress Core < 5.3.1 – Stored Cross-Site Scripting via Block Editor

WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the…

Versions affectées

[*, 3.7), 3.7-3.7.31, 3.8-3.8.31, 3.9-3.9.29, 4.0-4.0.28, 4.1-4.1.28, 4.2-4.2.25, 4.3-4.3.21, 4.4-4.4.20, 4.5-4.5.19, 4.6-4.6.16, 4.7-4.7.15, 4.8-4.8.11, 4.9-4.9.12, 5.0-5.0.7, 5.1-5.1.3, 5.2-5.2.4, 5.3

Correctif

3.7.32, 3.8.32, 3.9.30, 4.0.29, 4.1.29, 4.2.26, 4.3.22, 4.4.21, 4.5.20, 4.6.17, 4.7.16, 4.8.12, 4.9.13, 5.0.8, 5.1.4, 5.2.5, 5.3.1

Publication

13/12/2019

CVE-2019-20041 Moyenne · 6,4
WordPress

WordPress Core < 5.3.1 – Authenticated Stored Cross-Site Scripting

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript&colon; substring.

Versions affectées

[*, 3.7), 3.7-3.7.31, 3.8-3.8.31, 3.9-3.9.29, 4.0-4.0.28, 4.1-4.1.28, 4.2-4.2.25, 4.3-4.3.21, 4.4-4.4.20, 4.5-4.5.19, 4.6-4.6.16, 4.7-4.7.15, 4.8-4.8.11, 4.9-4.9.12, 5.0-5.0.7, 5.1-5.1.3, 5.2-5.2.4, 5.3

Correctif

3.7.32, 3.8.32, 3.9.30, 4.0.29, 4.1.29, 4.2.26, 4.3.22, 4.4.21, 4.5.20, 4.6.17, 4.7.16, 4.8.12, 4.9.13, 5.0.8, 5.1.4, 5.2.5, 5.3.1

Publication

13/12/2019

CVE-2019-16781 Moyenne · 5,8
WordPress

WordPress Core < 5.3.1 – Authenticated Stored Cross-Site Scripting

In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor…

Versions affectées

[*, 3.7), 3.7-3.7.31, 3.8-3.8.31, 3.9-3.9.29, 4.0-4.0.28, 4.1-4.1.28, 4.2-4.2.25, 4.3-4.3.21, 4.4-4.4.20, 4.5-4.5.19, 4.6-4.6.16, 4.7-4.7.15, 4.8-4.8.11, 4.9-4.9.12, 5.0-5.0.7, 5.1-5.1.3, 5.2-5.2.4

Correctif

3.7.32, 3.8.32, 3.9.30, 4.0.29, 4.1.29, 4.2.26, 4.3.22, 4.4.21, 4.5.20, 4.6.17, 4.7.16, 4.8.12, 4.9.13, 5.0.8, 5.1.4, 5.2.5, 5.3.1

Publication

13/12/2019

CVE-2019-20043 Moyenne · 4,3
WordPress

WordPress Core < 5.3.1 – Authorization Bypass

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role…

Versions affectées

[*, 3.7), 3.7-3.7.31, 3.8-3.8.31, 3.9-3.9.29, 4.0-4.0.28, 4.1-4.1.28, 4.2-4.2.25, 4.3-4.3.21, 4.4-4.4.20, 4.5-4.5.19, 4.6-4.6.16, 4.7-4.7.15, 4.8-4.8.11, 4.9-4.9.12, 5.0-5.0.7, 5.1-5.1.3, 5.2-5.2.4, 5.3

Correctif

3.7.32, 3.8.32, 3.9.30, 4.0.29, 4.1.29, 4.2.26, 4.3.22, 4.4.21, 4.5.20, 4.6.17, 4.7.16, 4.8.12, 4.9.13, 5.0.8, 5.1.4, 5.2.5, 5.3.1

Publication

01/12/2019

CVE-2019-17672 Moyenne · 6,4
WordPress

WordPress Core < 5.2.4 – Authenticated Stored Cross-Site Scripting

WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.

Versions affectées

[*, 3.7), 3.7-3.7.30, 3.8-3.8.30, 3.9-3.9.28, 4.0-4.0.27, 4.1-4.1.27, 4.2-4.2.24, 4.3-4.3.20, 4.4-4.4.19, 4.5-4.5.18, 4.6-4.6.15, 4.7-4.7.13, 4.7-4.7.14, 4.8-4.8.10, 4.9-4.9.11, 5.0-5.0.6, 5.1-5.1.2, 5.2-5.2.3

Correctif

3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.15, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4

Publication

14/10/2019

CVE-2019-17670 Moyenne · 5,4
WordPress

WordPress Core < 5.2.4 – Server Side Request Forgery #2

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.

Versions affectées

[*, 3.7), 3.7-3.7.30, 3.8-3.8.30, 3.9-3.9.28, 4.0-4.0.27, 4.1-4.1.27, 4.2-4.2.24, 4.3-4.3.20, 4.4-4.4.19, 4.5-4.5.18, 4.6-4.6.15, 4.7-4.7.13, 4.8-4.8.10, 4.9-4.9.11, 5.0-5.0.6, 5.1-5.1.2, 5.2-5.2.3

Correctif

3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.14, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4

Publication

14/10/2019

CVE-2019-17669 Moyenne · 5,4
WordPress

WordPress Core < 5.2.4 – Server Side Request Forgery

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.

Versions affectées

[*, 3.7), 3.7-3.7.30, 3.8-3.8.30, 3.9-3.9.28, 4.0-4.0.27, 4.1-4.1.27, 4.2-4.2.24, 4.3-4.3.20, 4.4-4.4.19, 4.5-4.5.18, 4.6-4.6.15, 4.7-4.7.13, 4.8-4.8.10, 4.9-4.9.11, 5.0-5.0.6, 5.1-5.1.2, 5.2-5.2.3

Correctif

3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.14, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4

Publication

14/10/2019

CVE-2019-17671 Moyenne · 5,3
WordPress

WordPress Core < 5.2.4 – Authorization Bypass

In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

Versions affectées

[*, 3.7), 3.7-3.7.30, 3.8-3.8.30, 3.9-3.9.28, 4.0-4.0.27, 4.1-4.1.27, 4.2-4.2.24, 4.3-4.3.20, 4.4-4.4.19, 4.5-4.5.18, 4.6-4.6.15, 4.7-4.7.14, 4.8-4.8.10, 4.9-4.9.11, 5.0-5.0.6, 5.1-5.1.2, 5.2-5.2.3

Correctif

3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.15, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4

Publication

14/10/2019

CVE-2019-17674 Moyenne · 5,5
WordPress

WordPress Core < 5.2.4 – Authenticated Stored Cross-Site Scripting via Customizer

WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.

Versions affectées

[*, 3.7), 3.7-3.7.30, 3.8-3.8.30, 3.9-3.9.28, 4.0-4.0.27, 4.1-4.1.27, 4.2-4.2.24, 4.3-4.3.20, 4.4-4.4.19, 4.5-4.5.18, 4.6-4.6.15, 4.7-4.7.14, 4.8-4.8.10, 4.9-4.9.11, 5.0-5.0.6, 5.1-5.1.2, 5.2-5.2.3

Correctif

3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.15, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4

Publication

14/10/2019

CVE-2019-17673 Élevée · 7,3
WordPress

WordPress Core < 5.2.4 – Cache Poisoning

WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.

Versions affectées

[*, 3.7), 3.7-3.7.30, 3.8-3.8.30, 3.9-3.9.28, 4.0-4.0.27, 4.1-4.1.27, 4.2-4.2.24, 4.3-4.3.20, 4.4-4.4.19, 4.5-4.5.18, 4.6-4.6.15, 4.7-4.7.14, 4.8-4.8.10, 4.9-4.9.11, 5.0-5.0.6, 5.1-5.1.2, 5.2-5.2.3

Correctif

3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.15, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4

Publication

14/10/2019

CVE-2019-17675 Moyenne · 5,5
WordPress

WordPress Core < 5.2.4 – Type Confusion

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

Versions affectées

*-3.6.1, 3.7-3.7.30, 3.8-3.8.30, 3.9-3.9.28, 4.0-4.0.27, 4.1-4.1.27, 4.2-4.2.24, 4.3-4.3.20, 4.4-4.4.19, 4.5-4.5.18, 4.6-4.6.15, 4.7-4.7.13, 4.8-4.8.10, 4.9-4.9.11, 5.0-5.0.6, 5.1-5.1.2, 5.2-5.2.3

Correctif

3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.14, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4

Publication

14/10/2019

CVE-2019-16219 Moyenne · 5,4
WordPress

WordPress Core < 5.2.3 – Reflected Cross-Site Scripting via Shortcode Previews

WordPress before 5.2.3 allows XSS in shortcode previews.

Versions affectées

[*, 3.7), 3.7-3.7.29, 3.8-3.8.29, 3.9-3.9.27, 4.0-4.0.26, 4.1-4.1.26, 4.2-4.2.23, 4.3-4.3.19, 4.4-4.4.18, 4.5-4.5.17, 4.6-4.6.13, 4.7-4.7.12, 4.8-4.8.9, 4.9-4.9.10, 5.0-5.0.5, 5.1-5.1.1, 5.2-5.2.2

Correctif

3.7.30, 3.8.30, 3.9.28, 4.0.27, 4.1.27, 4.2.24, 4.3.20, 4.4.19, 4.5.18, 4.6.15, 4.7.13, 4.8.10, 4.9.11, 5.0.6, 5.1.2, 5.2.3

Publication

05/09/2019

CVE-2019-16218 Élevée · 7,2
WordPress

WordPress Core < 5.2.3 – Stored Cross-Site Scripting via Comments

WordPress before 5.2.3 allows XSS in stored comments.

Versions affectées

[*, 3.7), 3.7-3.7.29, 3.8-3.8.29, 3.9-3.9.27, 4.0-4.0.26, 4.1-4.1.26, 4.2-4.2.23, 4.3-4.3.19, 4.4-4.4.18, 4.5-4.5.17, 4.6-4.6.13, 4.7-4.7.12, 4.8-4.8.9, 4.9-4.9.10, 5.0-5.0.5, 5.1-5.1.1, 5.2-5.2.2

Correctif

3.7.30, 3.8.30, 3.9.28, 4.0.27, 4.1.27, 4.2.24, 4.3.20, 4.4.19, 4.5.18, 4.6.15, 4.7.13, 4.8.10, 4.9.11, 5.0.6, 5.1.2, 5.2.3

Publication

05/09/2019

CVE-2019-16223 Moyenne · 5,4
WordPress

WordPress Core < 5.2.3 – Authenticated Cross-Site Scripting via Post Previews

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

Versions affectées

[*, 3.7), 3.7-3.7.29, 3.8-3.8.29, 3.9-3.9.27, 4.0-4.0.26, 4.1-4.1.26, 4.2-4.2.23, 4.3-4.3.19, 4.4-4.4.18, 4.5-4.5.17, 4.6-4.6.13, 4.7-4.7.13, 4.8-4.8.9, 4.9-4.9.10, 5.0-5.0.5, 5.1-5.1.1, 5.2-5.2.2

Correctif

3.7.30, 3.8.30, 3.9.28, 4.0.27, 4.1.27, 4.2.24, 4.3.20, 4.4.19, 4.5.18, 4.6.15, 4.7.14, 4.8.10, 4.9.11, 5.0.6, 5.1.2, 5.2.3

Publication

05/09/2019

CVE-2019-16220 Moyenne · 4,6
WordPress

WordPress Core < 5.2.3 – Open Redirect

In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect.

Versions affectées

[*, 3.7), 3.7-3.7.29, 3.8-3.8.29, 3.9-3.9.27, 4.0-4.0.26, 4.1-4.1.26, 4.2-4.2.23, 4.3-4.3.19, 4.4-4.4.18, 4.5-4.5.17, 4.6-4.6.13, 4.7-4.7.13, 4.8-4.8.9, 4.9-4.9.10, 5.0-5.0.5, 5.1-5.1.1, 5.2-5.2.2

Correctif

3.7.30, 3.8.30, 3.9.28, 4.0.27, 4.1.27, 4.2.24, 4.3.20, 4.4.19, 4.5.18, 4.6.15, 4.7.14, 4.8.10, 4.9.11, 5.0.6, 5.1.2, 5.2.3

Publication

05/09/2019

CVE-2019-16222 Moyenne · 6,4
WordPress

WordPress Core < 5.2.3 – Stored Cross-Site Scripting via Comments via URLs

WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.

Versions affectées

[*, 3.7), 3.7-3.7.29, 3.8-3.8.29, 3.9-3.9.27, 4.0-4.0.26, 4.1-4.1.26, 4.2-4.2.23, 4.3-4.3.19, 4.4-4.4.18, 4.5-4.5.17, 4.6-4.6.13, 4.7-4.7.13, 4.8-4.8.9, 4.9-4.9.10, 5.0-5.0.5, 5.1-5.1.1, 5.2-5.2.2

Correctif

3.7.30, 3.8.30, 3.9.28, 4.0.27, 4.1.27, 4.2.24, 4.3.20, 4.4.19, 4.5.18, 4.6.15, 4.7.14, 4.8.10, 4.9.11, 5.0.6, 5.1.2, 5.2.3

Publication

05/09/2019

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités