Répertoire de sécurité WordPress

Vulnérabilités du cœur WordPress, page 9

Consultez 380 vulnérabilités connues du cœur WordPress, avec CVE, gravité CVSS, versions affectées et correctifs disponibles. Page 9 de l’annuaire.

380Vulnérabilités
17Critiques
378Avec correctif
2Composants

WordPress Core

Failles et CVE du cœur WordPress

CVE-2017-5493 Moyenne · 5,3
WordPress

WordPress Core < 4.7.1 – Weak Multi-Site Activation Key for User and Site Signup

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2)…

Versions affectées

[*, 3.7), 3.7-3.7.16, 3.8-3.8.16, 3.9-3.9.14, 4.0-4.0.13, 4.1-4.1.13, 4.2-4.2.10, 4.3-4.3.6, 4.4-4.4.5, 4.5-4.5.4, 4.6-4.6.1, 4.7

Correctif

3.7.17, 3.8.17, 3.9.15, 4.0.14, 4.1.14, 4.2.11, 4.3.7, 4.4.6, 4.5.5, 4.6.2, 4.7.1

Publication

11/01/2017

CVE-2017-6514 Moyenne · 4,3
WordPress

WordPress Core < 4.7.2 – Path Disclosure

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

Versions affectées

[*, 3.7), 3.7-3.7.17, 3.8-3.8.17, 3.9-3.9.15, 4.0-4.0.14, 4.1-4.1.14, 4.2-4.2.11, 4.3-4.3.7, 4.4-4.4.6, 4.5-4.5.5, 4.6-4.6.2, 4.7-4.7.1

Correctif

3.7.18, 3.8.18, 3.9.16, 4.0.15, 4.1.15, 4.2.12, 4.3.8, 4.4.7, 4.5.6, 4.6.3, 4.7.2

Publication

01/01/2017

CVE-2016-7168 Moyenne · 4,8
WordPress

WordPress Core < 4.6.1 – Authenticated Stored Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted…

Versions affectées

[*, 3.7), 3.7-3.7.15, 3.8-3.8.15, 3.9-3.9.13, 4.0-4.0.12, 4.1-4.1.12, 4.2-4.2.9, 4.3-4.3.5, 4.4-4.4.4, 4.5-4.5.3, 4.6

Correctif

3.7.16, 3.8.16, 3.9.14, 4.0.13, 4.1.13, 4.2.10, 4.3.6, 4.4.5, 4.5.4, 4.6.1

Publication

07/09/2016

CVE-2016-7169 Moyenne · 6,5
WordPress

WordPress Core < 4.6.1 – Authenticated Directory Traversal to Arbitrary File Access

Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.

Versions affectées

[*, 3.7), 3.7-3.7.15, 3.8-3.8.15, 3.9-3.9.13, 4.0-4.0.12, 4.1-4.1.12, 4.2-4.2.9, 4.3-4.3.5, 4.4-4.4.4, 4.5-4.5.3, 4.6

Correctif

3.7.16, 3.8.16, 3.9.14, 4.0.13, 4.1.13, 4.2.10, 4.3.6, 4.4.5, 4.5.4, 4.6.1

Publication

07/09/2016

CVE-2016-6896 Moyenne · 6,5
WordPress

WordPress Core <= 4.5.3 – Denial of Service

Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to wp-admin/admin-ajax.php,…

Versions affectées

[*, 4.6)

Correctif

4.6

Publication

22/08/2016

CVE-2016-10148 Moyenne · 4,3
WordPress

WordPress Core < 4.6 – Authorization Bypass

The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to…

Versions affectées

[*, 4.6)

Correctif

4.6

Publication

16/08/2016

CVE-2016-6897 Élevée · 8,8
WordPress

WordPress Core < 4.6 – Cross-Site Request Forgery

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a…

Versions affectées

[*, 4.6)

Correctif

4.6

Publication

16/08/2016

CVE-2016-5833 Moyenne · 6,4
WordPress

WordPress Core < 4.5.3 – Cross-Site Scripting via Attachment Name #2

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

Versions affectées

[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2

Correctif

3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3

Publication

18/06/2016

CVE-2016-5838 Moyenne · 5,3
WordPress

WordPress Core < 4.5.3 – Password Change via Stolen Cookie

WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

Versions affectées

[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2

Correctif

3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3

Publication

18/06/2016

CVE-2016-5837 Moyenne · 5,4
WordPress

WordPress Core < 4.5.3 – Authorization Bypass to Remove Category Attribute

WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

Versions affectées

[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2

Correctif

3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3

Publication

18/06/2016

CVE-2016-5834 Moyenne · 6,4
WordPress

WordPress Core < 4.5.3 – Cross-Site Scripting via Attachment Name

Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

Versions affectées

[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2

Correctif

3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3

Publication

18/06/2016

CVE-2016-5836 Moyenne · 5,3
WordPress

WordPress Core < 4.5.3 – Denial of Service via oEmbed Protocol

The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.

Versions affectées

[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2

Correctif

3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3

Publication

18/06/2016

CVE-2016-5835 Moyenne · 4,3
WordPress

WordPress Core < 4.5.3 – Revision History Disclosure

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

Versions affectées

[*, 3.7), 3.7-3.7.14, 3.8-3.8.14, 3.9-3.9.12, 4.0-4.0.11, 4.1-4.1.11, 4.2-4.2.8, 4.3-4.3.4, 4.4-4.4.3, 4.5-4.5.2

Correctif

3.7.15, 3.8.15, 3.9.13, 4.0.12, 4.1.12, 4.2.9, 4.3.5, 4.4.4, 4.5.3

Publication

18/06/2016

CVE-2016-4566 Moyenne · 6,1
WordPress

WordPress Core < 4.5.2 – Cross-Site Scripting via plupload.flash.swf

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

Versions affectées

[*, 3.7), 3.7-3.7.13, 3.8-3.8.13, 3.9-3.9.11, 4.0-4.0.10, 4.1-4.1.10, 4.2-4.2.7, 4.3-4.3.3, 4.4-4.4.2, 4.5-4.5.1

Correctif

3.7.14, 3.8.14, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.4, 4.4.3, 4.5.2

Publication

06/05/2016

CVE-2016-4567 Moyenne · 6,4
WordPress

WordPress Core < 4.5.2 – Cross-Site Scripting via MediaElement.js

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

Versions affectées

[*, 3.7), 3.7-3.7.13, 3.8-3.8.13, 3.9-3.9.11, 4.0-4.0.10, 4.1-4.1.10, 4.2-4.2.7, 4.3-4.3.3, 4.4-4.4.2, 4.5-4.5.1

Correctif

3.7.14, 3.8.14, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.4, 4.4.3, 4.5.2

Publication

06/05/2016

Comprendre les données

Comment utiliser cet annuaire de vulnérabilités ?

Chaque fiche associe une vulnérabilité à un composant précis, avec sa gravité, les versions affectées et les versions corrigées lorsqu’elles sont connues. Les pages de wordpress servent de point d’entrée pour retrouver rapidement les composants concernés.

Une CVE ne signifie pas automatiquement qu’un site a été compromis. Elle indique qu’une version donnée peut être exposée. La bonne démarche consiste à vérifier l’inventaire réel, sauvegarder, mettre à jour, puis contrôler le fonctionnement et les journaux du site.

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités