Répertoire de sécurité WordPress
Vulnérabilités du cœur WordPress, page 8
Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 8 de l’annuaire.
WordPress Core
Failles et CVE du cœur WordPress
WordPress Core < 4.7.5 – Authorization Bypass Allowing Post Meta Updates
In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.
[*, 3.7), 3.7-3.7.20, 3.8-3.8.20, 3.9-3.9.18, 4.0-4.0.17, 4.1-4.1.17, 4.2-4.2.14, 4.3-4.3.10, 4.4-4.4.9, 4.5-4.5.8, 4.6-4.6.5, 4.7-4.7.4
3.7.21, 3.8.21, 3.9.19, 4.0.18, 4.1.18, 4.2.15, 4.3.11, 4.4.10, 4.5.9, 4.6.6, 4.7.5
16/05/2017
WordPress Core < 4.7.5 – Cross-Site Request Forgery Filesystem Credential Update
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.
[*, 3.7), 3.7-3.7.20, 3.8-3.8.20, 3.9-3.9.18, 4.0-4.0.17, 4.1-4.1.17, 4.2-4.2.14, 4.3-4.3.10, 4.4-4.4.9, 4.5-4.5.8, 4.6-4.6.5, 4.7-4.7.4
3.7.21, 3.8.21, 3.9.19, 4.0.18, 4.1.18, 4.2.15, 4.3.11, 4.4.10, 4.5.9, 4.6.6, 4.7.5
16/05/2017
WordPress Core < 4.7.5 – Stored Cross-Site Scripting via filenames
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.
*-3.7.20, 3.8-3.8.20, 3.9-3.9.18, 4.0-4.0.17, 4.1-4.1.17, 4.2-4.2.14, 4.3-4.3.10, 4.4-4.4.9, 4.5-4.5.8, 4.6-4.6.5, 4.7-4.7.4
3.7.21, 3.8.21, 3.9.19, 4.0.18, 4.1.18, 4.2.15, 4.3.11, 4.4.10, 4.5.9, 4.6.6, 4.7.5
16/05/2017
Wordpress Core < 5.5 – Unauthorized Password Reset via Interception
WordPress up to version 5.5 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this…
[*, 5.5)
5.5
03/05/2017
WordPress Core < 4.7.3 – Arbitrary File Deletion
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2
3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3
06/03/2017
WordPress Core < 4.7.3 – Cross-Site Scripting via Taxonomy names
In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2
3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3
06/03/2017
WordPress Core < 4.7.3 – Cross-Site Request Forgery via Press This
In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an outbound HTTP request for a large file that is then parsed by…
[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2
3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3
06/03/2017
WordPress Core < 4.7.3 – Cross-Site Scripting via Media Metadata
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in…
[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2
3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3
06/03/2017
WordPress Core < 4.7.3 – Bypass URL Validation
In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.
[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2
3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3
06/03/2017
WordPress Core < 4.7.3 – Authenticated Cross-Site Scripting in Youtube URL Embeds
In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2
3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3
06/03/2017
WordPress Core < 4.7.2 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.
[*, 3.7), 3.7-3.7.17, 3.8-3.8.17, 3.9-3.9.15, 4.0-4.0.14, 4.1-4.1.14, 4.2-4.2.11, 4.3-4.3.7, 4.4-4.4.6, 4.5-4.5.5, 4.6-4.6.2, 4.7-4.7.1
3.7.18, 3.8.18, 3.9.16, 4.0.15, 4.1.15, 4.2.12, 4.3.8, 4.4.7, 4.5.6, 4.6.3, 4.7.2
26/01/2017
WordPress Core < 4.7.2 – Authenticated SQL Injection
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.
[*, 3.7), 3.7-3.7.17, 3.8-3.8.17, 3.9-3.9.15, 4.0-4.0.14, 4.1-4.1.14, 4.2-4.2.11, 4.3-4.3.7, 4.4-4.4.6, 4.5-4.5.5, 4.6-4.6.2, 4.7-4.7.1
3.7.18, 3.8.18, 3.9.16, 4.0.15, 4.1.15, 4.2.12, 4.3.8, 4.4.7, 4.5.6, 4.6.3, 4.7.2
26/01/2017
WordPress Core < 4.7.2 – Authorization Bypass to Term Disclosure
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
[*, 3.7), 3.7-3.7.17, 3.8-3.8.17, 3.9-3.9.15, 4.0-4.0.14, 4.1-4.1.14, 4.2-4.2.11, 4.3-4.3.7, 4.4-4.4.6, 4.5-4.5.5, 4.6-4.6.2, 4.7-4.7.1
3.7.18, 3.8.18, 3.9.16, 4.0.15, 4.1.15, 4.2.12, 4.3.8, 4.4.7, 4.5.6, 4.6.3, 4.7.2
26/01/2017
WordPress Core < 4.7.2 – Arbitrary Page Modification
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts followed by a numeric value…
[*, 3.7), 3.7-3.7.17, 3.8-3.8.17, 3.9-3.9.15, 4.0-4.0.14, 4.1-4.1.14, 4.2-4.2.11, 4.3-4.3.7, 4.4-4.4.6, 4.5-4.5.5, 4.6-4.6.2, 4.7-4.7.1
3.7.18, 3.8.18, 3.9.16, 4.0.15, 4.1.15, 4.2.12, 4.3.8, 4.4.7, 4.5.6, 4.6.3, 4.7.2
26/01/2017
WordPress Core < 4.7.1 – Authorization Bypass
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7
3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1
11/01/2017
WordPress Core < 4.7.1 – Cross-Site Scripting via Name and Version Header of Plugin
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.
[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7
3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1
11/01/2017
WordPress Core < 4.7.1 – Stored Cross-Site Scripting via theme directory name
Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.
[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7
3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1
11/01/2017
WordPress Core < 4.7.1 – Cross-Site Request Forgery via Uploading Flash File
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.
[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7
3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1
11/01/2017
WordPress Core < 4.7.1 – Cross-Site Request Forgery via Widget Editing
Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.
[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7
3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1
11/01/2017
WordPress Core < 4.7.1 – Information Disclosure
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7
3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1
11/01/2017
Comprendre les données
Comment utiliser cet annuaire de vulnérabilités ?
Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.
Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.