Répertoire de sécurité WordPress
Vulnérabilités du cœur WordPress, page 9
Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 9 de l’annuaire.
WordPress Core
Failles et CVE du cœur WordPress
WordPress Core < 4.7.1 – Weak Multi-Site Activation Key for User and Site Signup
wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2)…
[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7
3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1
11/01/2017
WordPress Core < 4.7.2 – Path Disclosure
WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.
[*, 3.7), 3.7-3.7.17, 3.8-3.8.17, 3.9-3.9.15, 4.0-4.0.14, 4.1-4.1.14, 4.2-4.2.11, 4.3-4.3.7, 4.4-4.4.6, 4.5-4.5.5, 4.6-4.6.2, 4.7-4.7.1
3.7.18, 3.8.18, 3.9.16, 4.0.15, 4.1.15, 4.2.12, 4.3.8, 4.4.7, 4.5.6, 4.6.3, 4.7.2
01/01/2017
WordPress Core < 4.5 – Server-Side Request Forgery
WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.
[*, 4.5)
4.5
29/09/2016
WordPress Core < 4.6.1 – Authenticated Stored Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted…
[*, 3.7), 3.7-3.7.15, 3.8-3.8.15, 3.9-3.9.13, 4.0-4.0.12, 4.1-4.1.12, 4.2-4.2.9, 4.3-4.3.5, 4.4-4.4.4, 4.5-4.5.3, 4.6
3.7.16, 3.8.16, 3.9.14, 4.0.13, 4.1.13, 4.2.10, 4.3.6, 4.4.5, 4.5.4, 4.6.1
07/09/2016
WordPress Core < 4.6.1 – Authenticated Directory Traversal to Arbitrary File Access
Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.
[*, 3.7), 3.7-3.7.15, 3.8-3.8.15, 3.9-3.9.13, 4.0-4.0.12, 4.1-4.1.12, 4.2-4.2.9, 4.3-4.3.5, 4.4-4.4.4, 4.5-4.5.3, 4.6
3.7.16, 3.8.16, 3.9.14, 4.0.13, 4.1.13, 4.2.10, 4.3.6, 4.4.5, 4.5.4, 4.6.1
07/09/2016
WordPress Core <= 4.5.3 – Denial of Service
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to wp-admin/admin-ajax.php,…
[*, 4.6)
4.6
22/08/2016
WordPress Core < 4.6 – Authorization Bypass
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to…
[*, 4.6)
4.6
16/08/2016
WordPress Core < 4.6 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a…
[*, 4.6)
4.6
16/08/2016
WordPress Core < 4.5.3 – Cross-Site Scripting via Attachment Name #2
Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.
[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2
3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3
18/06/2016
WordPress Core < 4.5.3 – Password Change via Stolen Cookie
WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.
[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2
3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3
18/06/2016
WordPress Core < 4.5.3 – Authorization Bypass to Remove Category Attribute
WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.
[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2
3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3
18/06/2016
WordPress Core < 4.5.3 – Cross-Site Scripting via Attachment Name
Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.
[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2
3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3
18/06/2016
WordPress Core < 4.5.3 – Bypass sanitize_file_name Protection
WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.
[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2
3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3
18/06/2016
WordPress Core < 4.5.3 – Denial of Service via oEmbed Protocol
The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.
[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2
3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3
18/06/2016
WordPress Core < 4.5.3 – Cross-Site Scripting via Customizer
The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.
[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2
3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3
18/06/2016
WordPress Core < 4.5.3 – Revision History Disclosure
WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.
[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2
3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3
18/06/2016
WordPress Core < 4.5.2 – Cross-Site Scripting via plupload.flash.swf
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
[*, 3.7), 3.7-3.7.13, 3.8-3.8.13, 3.9-3.9.11, 4.0-4.0.10, 4.1-4.1.10, 4.2-4.2.7, 4.3-4.3.3, 4.4-4.4.2, 4.5-4.5.1
3.7.14, 3.8.14, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.4, 4.4.3, 4.5.2
06/05/2016
WordPress Core < 4.5.2 – Cross-Site Scripting via MediaElement.js
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."
[*, 3.7), 3.7-3.7.13, 3.8-3.8.13, 3.9-3.9.11, 4.0-4.0.10, 4.1-4.1.10, 4.2-4.2.7, 4.3-4.3.3, 4.4-4.4.2, 4.5-4.5.1
3.7.14, 3.8.14, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.4, 4.4.3, 4.5.2
06/05/2016
WordPress Core < 4.5 – Cross-Site Scripting via Network Settings Page
Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
[*, 4.5)
4.5
12/04/2016
WordPress Core < 4.5 – Cross-Site Request Forgery via wp_ajax_wp_compression_test
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.
[*, 4.5)
4.5
12/03/2016
Comprendre les données
Comment utiliser cet annuaire de vulnérabilités ?
Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.
Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.