Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 7

Consultez 389 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 7 de l’annuaire.

389Vulnérabilités
17Critiques
387Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

CVE-2018-20148 Élevée · 8,8
WordPress

WordPress Core < 5.0.1 – PHP Object Injection

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function…

Versions affectées

[*, 3.7), 3.7-3.7.27, 3.8-3.8.27, 3.9-3.9.25, 4.0-4.0.24, 4.1-4.1.24, 4.2-4.2.21, 4.3-4.3.17, 4.4-4.4.16, 4.5-4.5.15, 4.6-4.6.12, 4.7-4.7.11, 4.8-4.8.7, 4.9-4.9.8, 5.0

Correctif

3.7.28, 3.8.28, 3.9.26, 4.0.25, 4.1.25, 4.2.22, 4.3.18, 4.4.17, 4.5.16, 4.6.13, 4.7.12, 4.8.8, 4.9.9, 5.0.1

Publication

12/12/2018

CVE-2018-1000773 Élevée · 7,5
WordPress

WordPress Core < 5.0.1 – PHAR Unserialization

WordPress Core versions before 5.0.1 contain a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail upload by…

Versions affectées

[*, 3.7), 3.7-3.7.27, 3.8-3.8.27, 3.9-3.9.25, 4.0-4.0.24, 4.1-4.1.24, 4.2-4.2.21, 4.3-4.3.17, 4.4-4.4.16, 4.5-4.5.15, 4.6-4.6.12, 4.7-4.7.11, 4.8-4.8.7, 4.9-4.9.8, 5.0

Correctif

3.7.28, 3.8.28, 3.9.26, 4.0.25, 4.1.25, 4.2.22, 4.3.18, 4.4.17, 4.5.16, 4.6.13, 4.7.12, 4.8.8, 4.9.9, 5.0.1

Publication

06/09/2018

CVE-2018-14028 Informationnelle
WordPress

WordPress Core < 6.4.3 – Authenticated(Administrator+) PHP File Upload

In all current versions of WordPress Core before 6.4.3, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin…

Versions affectées

[*, 4.1), 4.1-4.1.39, 4.2-4.2.36, 4.3-4.3.32, 4.4-4.4.31, 4.5-4.5.30, 4.6-4.6.27, 4.7-4.7.27, 4.8-4.8.23, 4.9-4.9.24, 5.0-5.0.20, 5.1-5.1.17, 5.2-5.2.19, 5.3-5.3.16, 5.4-5.4.14, 5.5-5.5.13, 5.6-5.6.12, 5.7-5.7.10, 5.8-5.8.8, 5.9-5.9.8, 6.0-6.0.6, 6.1-6.1.4, 6.2-6.2.3, 6.3-6.3.2, 6.4-6.4.2

Correctif

4.1.40, 4.2.37, 4.3.33, 4.4.32, 4.5.31, 4.6.28, 4.7.28, 4.8.24, 4.9.25, 5.0.21, 5.1.18, 5.2.20, 5.3.17, 5.4.15, 5.5.14, 5.6.13, 5.7.11, 5.8.9, 5.9.9, 6.0.7, 6.1.5, 6.2.4, 6.3.3, 6.4.3

Publication

04/08/2018

CVE-2018-12895 Élevée · 8,8
WordPress

WordPress Core < 4.9.7 – Authenticated Arbitrary File Deletion

WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing…

Versions affectées

[*, 3.7), 3.7-3.7.26, 3.8-3.8.26, 3.9-3.9.24, 4.0-4.0.23, 4.1-4.1.23, 4.2-4.2.20, 4.3-4.3.16, 4.4-4.4.15, 4.5-4.5.14, 4.6-4.6.11, 4.7-4.7.10, 4.8-4.8.6, 4.9-4.9.6

Correctif

3.7.27, 3.8.27, 3.9.25, 4.0.24, 4.1.24, 4.2.21, 4.3.17, 4.4.16, 4.5.15, 4.6.12, 4.7.11, 4.8.7, 4.9.7

Publication

05/07/2018

CVE-2018-10100 Moyenne · 5,4
WordPress

WordPress Core < 4.9.5 – Open Redirect

Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.

Versions affectées

[*, 3.7), 3.7-3.7.25, 3.8-3.8.25, 3.9-3.9.23, 4.0-4.0.22, 4.1-4.1.22, 4.2-4.2.19, 4.3-4.3.15, 4.4-4.4.14, 4.5-4.5.13, 4.6-4.6.10, 4.7-4.7.9, 4.8-4.8.5, 4.9-4.9.4

Correctif

3.7.26, 3.8.26, 3.9.24, 4.0.23, 4.1.23, 4.2.20, 4.3.16, 4.4.15, 4.5.14, 4.6.11, 4.7.10, 4.8.6, 4.9.5

Publication

03/04/2018

CVE-2018-10102 Moyenne · 6,4
WordPress

WordPress Core < 4.9.5 – Authenticated Stored Cross-Site Scripting via Generator Tag

Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.

Versions affectées

[*, 3.7), 3.7-3.7.25, 3.8-3.8.25, 3.9-3.9.23, 4.0-4.0.22, 4.1-4.1.22, 4.2-4.2.19, 4.3-4.3.15, 4.4-4.4.14, 4.5-4.5.13, 4.6-4.6.10, 4.7-4.7.9, 4.8-4.8.5, 4.9-4.9.4

Correctif

3.7.26, 3.8.26, 3.9.24, 4.0.23, 4.1.23, 4.2.20, 4.3.16, 4.4.15, 4.5.14, 4.6.11, 4.7.10, 4.8.6, 4.9.5

Publication

03/04/2018

CVE-2018-10101 Moyenne · 4,3
WordPress

WordPress Core < 4.9.5 – Security Misconfiguration with URL Hostnames

Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.

Versions affectées

[*, 3.7), 3.7-3.7.25, 3.8-3.8.25, 3.9-3.9.23, 4.0-4.0.22, 4.1-4.1.22, 4.2-4.2.19, 4.3-4.3.15, 4.4-4.4.14, 4.5-4.5.13, 4.6-4.6.10, 4.7-4.7.9, 4.8-4.8.5, 4.9-4.9.4

Correctif

3.7.26, 3.8.26, 3.9.24, 4.0.23, 4.1.23, 4.2.20, 4.3.16, 4.4.15, 4.5.14, 4.6.11, 4.7.10, 4.8.6, 4.9.5

Publication

03/04/2018

CVE-2018-6389 Élevée · 7,5
WordPress

WordPress Core < 5.0 – Denial of Service

In WordPress before 5.0, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times. It…

Versions affectées

[*, 5.0)

Correctif

5.0

Publication

05/02/2018

CVE-2018-5776 Moyenne · 6,4
WordPress

WordPress Core < 4.9.2 – Authenticated Cross-Site Scripting

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

Versions affectées

*-3.6.1, 3.7-3.7.24, 3.8-3.8.24, 3.9-3.9.22, 4.0-4.0.21, 4.1-4.1.21, 4.2-4.2.18, 4.3-4.3.14, 4.4-4.4.13, 4.5-4.5.12, 4.6-4.6.9, 4.7-4.7.8, 4.8-4.8.4, 4.9-4.9.1

Correctif

3.7.25, 3.8.25, 3.9.23, 4.0.22, 4.1.22, 4.2.19, 4.3.15, 4.4.14, 4.5.13, 4.6.10, 4.7.9, 4.8.5, 4.9.2

Publication

16/01/2018

CVE-2017-17092 Moyenne · 6,4
WordPress

WordPress Core < 4.9.1 – Authenticated Stored Cross-Site Scripting

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

Versions affectées

[*, 3.7), 3.7-3.7.23, 3.8-3.8.23, 3.9-3.9.21, 4.0-4.0.20, 4.1-4.1.20, 4.2-4.2.17, 4.3-4.3.13, 4.4-4.4.12, 4.5-4.5.11, 4.6-4.6.8, 4.7-4.7.7, 4.8-4.8.3, 4.9

Correctif

3.7.24, 3.8.24, 3.9.22, 4.0.21, 4.1.21, 4.2.18, 4.3.14, 4.4.13, 4.5.12, 4.6.9, 4.7.8, 4.8.4, 4.9.1

Publication

29/11/2017

CVE-2017-17093 Moyenne · 6,4
WordPress

WordPress Core < 4.9.1- Stored Cross-Site Scripting via Language

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

Versions affectées

[*, 3.7), 3.7-3.7.23, 3.8-3.8.23, 3.9-3.9.21, 4.0-4.0.20, 4.1-4.1.20, 4.2-4.2.17, 4.3-4.3.13, 4.4-4.4.12, 4.5-4.5.11, 4.6-4.6.8, 4.7-4.7.7, 4.8-4.8.3, 4.9

Correctif

3.7.24, 3.8.24, 3.9.22, 4.0.21, 4.1.21, 4.2.18, 4.3.14, 4.4.13, 4.5.12, 4.6.9, 4.7.8, 4.8.4, 4.9.1

Publication

29/11/2017

CVE-2017-17091 Moyenne · 5,4
WordPress

WordPress Core < 4.9.1 – Authorization Bypass

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

Versions affectées

[*, 3.7), 3.7-3.7.23, 3.8-3.8.23, 3.9-3.9.21, 4.0-4.0.20, 4.1-4.1.20, 4.2-4.2.17, 4.3-4.3.13, 4.4-4.4.12, 4.5-4.5.11, 4.6-4.6.8, 4.7-4.7.7, 4.8-4.8.3, 4.9

Correctif

3.7.24, 3.8.24, 3.9.22, 4.0.21, 4.1.21, 4.2.18, 4.3.14, 4.4.13, 4.5.12, 4.6.9, 4.7.8, 4.8.4, 4.9.1

Publication

29/11/2017

CVE-2017-17094 Moyenne · 6,1
WordPress

WordPress Core < 4.9.1 – Reflected Cross-Site Scripting

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

Versions affectées

[*, 3.7), 3.7-3.7.23, 3.8-3.8.23, 3.9-3.9.21, 4.0-4.0.20, 4.1-4.1.20, 4.2-4.2.17, 4.3-4.3.13, 4.4-4.4.12, 4.5-4.5.11, 4.6-4.6.8, 4.7-4.7.7, 4.8-4.8.3, 4.9

Correctif

3.7.24, 3.8.24, 3.9.22, 4.0.21, 4.1.21, 4.2.18, 4.3.14, 4.4.13, 4.5.12, 4.6.9, 4.7.8, 4.8.4, 4.9.1

Publication

29/11/2017

CVE-2017-16510 Critique · 9,8
WordPress

WordPress Core < 4.8.3 – SQL Injection due to Double Prepare approach

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.

Versions affectées

[*, 3.7), 3.7-3.7.22, 3.8-3.8.22, 3.9-3.9.20, 4.0-4.0.19, 4.1-4.1.19, 4.2-4.2.16, 4.3-4.3.12, 4.4-4.4.11, 4.5-4.5.10, 4.6-4.6.7, 4.7-4.7.6, 4.8-4.8.2

Correctif

3.7.23, 3.8.23, 3.9.21, 4.0.20, 4.1.20, 4.2.17, 4.3.13, 4.4.12, 4.5.11, 4.6.8, 4.7.7, 4.8.3

Publication

31/10/2017

CVE-2017-14990 Informationnelle
WordPress

WordPress Core – All Known Versions – Cleartext Storage of wp_signups.activation_key

All known versions of WordPress Core store cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as…

Versions affectées

*

Correctif

Non indiqué

Publication

10/10/2017

CVE-2016-9263 Moyenne · 4,7
WordPress

WordPress Core < 4.9.1 – Cross-domain Flash injection

WordPress through 4.9.1, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

Versions affectées

[*, 3.7), 3.7-3.7.24, 3.8-3.8.24, 3.9-3.9.23, 4.0-4.0.21, 4.1-4.1.21, 4.2-4.2.18, 4.3-4.3.14, 4.4-4.4.13, 4.5-4.5.12, 4.6-4.6.9, 4.7-4.7.8, 4.8-4.8.4, 4.9-4.9.1

Correctif

3.7.25, 3.8.25, 3.9.24, 4.0.22, 4.1.22, 4.2.19, 4.3.15, 4.4.14, 4.5.13, 4.6.10, 4.7.9, 4.8.5, 4.9.2

Publication

10/10/2017

CVE-2017-14718 Moyenne · 6,4
WordPress

WordPress Core < 4.8.2 – Cross-Site Scripting via Javascript: and Data: URLs

Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.

Versions affectées

[*, 3.7), 3.7-3.7.21, 3.8-3.8.21, 3.9-3.9.19, 4.0-4.0.18, 4.1-4.1.18, 4.2-4.2.15, 4.3-4.3.11, 4.4-4.4.10, 4.5-4.5.9, 4.6-4.6.6, 4.7-4.7.5, 4.8-4.8.1

Correctif

3.7.22, 3.8.22, 3.9.20, 4.0.19, 4.1.19, 4.2.16, 4.3.12, 4.4.11, 4.5.10, 4.6.7, 4.7.6, 4.8.2

Publication

19/09/2017

CVE-2017-14724 Moyenne · 6,4
WordPress

WordPress Core < 4.8.2 – Cross-Site Scripting in oEmbed

Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.

Versions affectées

[*, 3.7), 3.7-3.7.21, 3.8-3.8.21, 3.9-3.9.19, 4.0-4.0.18, 4.1-4.1.18, 4.2-4.2.15, 4.3-4.3.11, 4.4-4.4.10, 4.5-4.5.9, 4.6-4.6.6, 4.7-4.7.5, 4.8-4.8.1

Correctif

3.7.22, 3.8.22, 3.9.20, 4.0.19, 4.1.19, 4.2.16, 4.3.12, 4.4.11, 4.5.10, 4.6.7, 4.7.6, 4.8.2

Publication

19/09/2017

CVE-2017-14720 Moyenne · 6,4
WordPress

WordPress Core < 4.8.2 – Cross-Site Scripting via Template Name

Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.

Versions affectées

[*, 3.7), 3.7-3.7.21, 3.8-3.8.21, 3.9-3.9.19, 4.0-4.0.18, 4.1-4.1.18, 4.2-4.2.15, 4.3-4.3.11, 4.4-4.4.10, 4.5-4.5.9, 4.6-4.6.6, 4.7-4.7.5, 4.8-4.8.1

Correctif

3.7.22, 3.8.22, 3.9.20, 4.0.19, 4.1.19, 4.2.16, 4.3.12, 4.4.11, 4.5.10, 4.6.7, 4.7.6, 4.8.2

Publication

19/09/2017

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités