Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 8

Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 8 de l’annuaire.

380Vulnérabilités
17Critiques
378Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

CVE-2017-9065 Moyenne · 5,4
WordPress

WordPress Core < 4.7.5 – Authorization Bypass Allowing Post Meta Updates

In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.

Versions affectées

[*, 3.7), 3.7-3.7.20, 3.8-3.8.20, 3.9-3.9.18, 4.0-4.0.17, 4.1-4.1.17, 4.2-4.2.14, 4.3-4.3.10, 4.4-4.4.9, 4.5-4.5.8, 4.6-4.6.5, 4.7-4.7.4

Correctif

3.7.21, 3.8.21, 3.9.19, 4.0.18, 4.1.18, 4.2.15, 4.3.11, 4.4.10, 4.5.9, 4.6.6, 4.7.5

Publication

16/05/2017

CVE-2017-9064 Élevée · 8,8
WordPress

WordPress Core < 4.7.5 – Cross-Site Request Forgery Filesystem Credential Update

In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.

Versions affectées

[*, 3.7), 3.7-3.7.20, 3.8-3.8.20, 3.9-3.9.18, 4.0-4.0.17, 4.1-4.1.17, 4.2-4.2.14, 4.3-4.3.10, 4.4-4.4.9, 4.5-4.5.8, 4.6-4.6.5, 4.7-4.7.4

Correctif

3.7.21, 3.8.21, 3.9.19, 4.0.18, 4.1.18, 4.2.15, 4.3.11, 4.4.10, 4.5.9, 4.6.6, 4.7.5

Publication

16/05/2017

CVE-2017-9061 Moyenne · 6,4
WordPress

WordPress Core < 4.7.5 – Stored Cross-Site Scripting via filenames

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

Versions affectées

*-3.7.20, 3.8-3.8.20, 3.9-3.9.18, 4.0-4.0.17, 4.1-4.1.17, 4.2-4.2.14, 4.3-4.3.10, 4.4-4.4.9, 4.5-4.5.8, 4.6-4.6.5, 4.7-4.7.4

Correctif

3.7.21, 3.8.21, 3.9.19, 4.0.18, 4.1.18, 4.2.15, 4.3.11, 4.4.10, 4.5.9, 4.6.6, 4.7.5

Publication

16/05/2017

CVE-2017-6816 Moyenne · 4,9
WordPress

WordPress Core < 4.7.3 – Arbitrary File Deletion

In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.

Versions affectées

[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2

Correctif

3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3

Publication

06/03/2017

CVE-2017-6818 Moyenne · 6,4
WordPress

WordPress Core < 4.7.3 – Cross-Site Scripting via Taxonomy names

In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.

Versions affectées

[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2

Correctif

3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3

Publication

06/03/2017

CVE-2017-6819 Élevée · 8,8
WordPress

WordPress Core < 4.7.3 – Cross-Site Request Forgery via Press This

In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an outbound HTTP request for a large file that is then parsed by…

Versions affectées

[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2

Correctif

3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3

Publication

06/03/2017

CVE-2017-6814 Moyenne · 6,4
WordPress

WordPress Core < 4.7.3 – Cross-Site Scripting via Media Metadata

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in…

Versions affectées

[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2

Correctif

3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3

Publication

06/03/2017

CVE-2017-6815 Moyenne · 6,1
WordPress

WordPress Core < 4.7.3 – Bypass URL Validation

In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.

Versions affectées

[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2

Correctif

3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3

Publication

06/03/2017

CVE-2017-6817 Moyenne · 6,4
WordPress

WordPress Core < 4.7.3 – Authenticated Cross-Site Scripting in Youtube URL Embeds

In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.

Versions affectées

[*, 3.7), 3.7-3.7.18, 3.8-3.8.18, 3.9-3.9.16, 4.0-4.0.15, 4.1-4.1.15, 4.2-4.2.12, 4.3-4.3.8, 4.4-4.4.7, 4.5-4.5.6, 4.6-4.6.3, 4.7-4.7.2

Correctif

3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3

Publication

06/03/2017

CVE-2017-5612 Moyenne · 6,1
WordPress

WordPress Core < 4.7.2 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted excerpt.

Versions affectées

[*, 3.7), 3.7-3.7.17, 3.8-3.8.17, 3.9-3.9.15, 4.0-4.0.14, 4.1-4.1.14, 4.2-4.2.11, 4.3-4.3.7, 4.4-4.4.6, 4.5-4.5.5, 4.6-4.6.2, 4.7-4.7.1

Correctif

3.7.18, 3.8.18, 3.9.16, 4.0.15, 4.1.15, 4.2.12, 4.3.8, 4.4.7, 4.5.6, 4.6.3, 4.7.2

Publication

26/01/2017

CVE-2017-5611 Élevée · 8,8
WordPress

WordPress Core < 4.7.2 – Authenticated SQL Injection

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

Versions affectées

[*, 3.7), 3.7-3.7.17, 3.8-3.8.17, 3.9-3.9.15, 4.0-4.0.14, 4.1-4.1.14, 4.2-4.2.11, 4.3-4.3.7, 4.4-4.4.6, 4.5-4.5.5, 4.6-4.6.2, 4.7-4.7.1

Correctif

3.7.18, 3.8.18, 3.9.16, 4.0.15, 4.1.15, 4.2.12, 4.3.8, 4.4.7, 4.5.6, 4.6.3, 4.7.2

Publication

26/01/2017

CVE-2017-5610 Moyenne · 4,3
WordPress

WordPress Core < 4.7.2 – Authorization Bypass to Term Disclosure

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.

Versions affectées

[*, 3.7), 3.7-3.7.17, 3.8-3.8.17, 3.9-3.9.15, 4.0-4.0.14, 4.1-4.1.14, 4.2-4.2.11, 4.3-4.3.7, 4.4-4.4.6, 4.5-4.5.5, 4.6-4.6.2, 4.7-4.7.1

Correctif

3.7.18, 3.8.18, 3.9.16, 4.0.15, 4.1.15, 4.2.12, 4.3.8, 4.4.7, 4.5.6, 4.6.3, 4.7.2

Publication

26/01/2017

CVE-2017-1001000 Élevée · 7,3
WordPress

WordPress Core < 4.7.2 – Arbitrary Page Modification

The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts followed by a numeric value…

Versions affectées

[*, 3.7), 3.7-3.7.17, 3.8-3.8.17, 3.9-3.9.15, 4.0-4.0.14, 4.1-4.1.14, 4.2-4.2.11, 4.3-4.3.7, 4.4-4.4.6, 4.5-4.5.5, 4.6-4.6.2, 4.7-4.7.1

Correctif

3.7.18, 3.8.18, 3.9.16, 4.0.15, 4.1.15, 4.2.12, 4.3.8, 4.4.7, 4.5.6, 4.6.3, 4.7.2

Publication

26/01/2017

CVE-2017-5491 Élevée · 8,3
WordPress

WordPress Core < 4.7.1 – Authorization Bypass

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

Versions affectées

[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7

Correctif

3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1

Publication

11/01/2017

CVE-2017-5488 Moyenne · 5,5
WordPress

WordPress Core < 4.7.1 – Cross-Site Scripting via Name and Version Header of Plugin

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.

Versions affectées

[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7

Correctif

3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1

Publication

11/01/2017

CVE-2017-5490 Moyenne · 5,5
WordPress

WordPress Core < 4.7.1 – Stored Cross-Site Scripting via theme directory name

Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.

Versions affectées

[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7

Correctif

3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1

Publication

11/01/2017

CVE-2017-5489 Élevée · 8,8
WordPress

WordPress Core < 4.7.1 – Cross-Site Request Forgery via Uploading Flash File

Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.

Versions affectées

[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7

Correctif

3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1

Publication

11/01/2017

CVE-2017-5492 Élevée · 8,8
WordPress

WordPress Core < 4.7.1 – Cross-Site Request Forgery via Widget Editing

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.

Versions affectées

[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7

Correctif

3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1

Publication

11/01/2017

CVE-2017-5487 Moyenne · 4,3
WordPress

WordPress Core < 4.7.1 – Information Disclosure

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

Versions affectées

[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7

Correctif

3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1

Publication

11/01/2017

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités