{"id":18804,"date":"2020-09-03T12:15:22","date_gmt":"2020-09-03T09:15:22","guid":{"rendered":"http:\/\/content.freeplanetvpn.com\/?p=18804"},"modified":"2022-03-28T23:58:55","modified_gmt":"2022-03-28T20:58:55","slug":"les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress","status":"publish","type":"post","link":"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/","title":{"rendered":"Les pirates informatiques exploitent les vuln\u00e9rabilit\u00e9s critiques des sites WordPress"},"content":{"rendered":"<p><img decoding=\"async\" class=\"wp-image-34948 aligncenter\" src=\"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791.webp\" alt=\"\" width=\"641\" height=\"356\" srcset=\"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791.webp 791w, https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791-300x166.webp 300w, https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791-768x426.webp 768w, https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791-640x355.webp 640w\" sizes=\"(max-width: 641px) 100vw, 641px\" \/><\/p>\n<p>L&#8217;inconv\u00e9nient est le gestionnaire de fichiers, un plugin qui compte plus de 700 000 utilisateurs, dont 52% souffrent.<\/p>\n<p>Les pirates exploitent activement une vuln\u00e9rabilit\u00e9 qui leur permet d&#8217;ex\u00e9cuter des commandes et des scripts malveillants sur des sites web utilisant <a href=\"https:\/\/wordpress.org\/plugins\/wp-file-manager\/\" target=\"_blank\" rel=\"noopener noreferrer\">File Manager<\/a>, un plugin WordPress avec plus de 700 000 installations actives, ont d\u00e9clar\u00e9 les chercheurs mardi. Le mot des attaques est arriv\u00e9 quelques heures apr\u00e8s que la faille de s\u00e9curit\u00e9 ait \u00e9t\u00e9 corrig\u00e9e.<\/p>\n<p>Les attaquants utilisent l&#8217;exploit pour t\u00e9l\u00e9charger des fichiers contenant des coquilles web cach\u00e9es dans une image. De l\u00e0, ils disposent d&#8217;une interface pratique qui leur permet d&#8217;ex\u00e9cuter des commandes dans <span style=\"font-weight: 400;\">plugins\/wp-file-manager\/lib\/files\/<\/span>, le r\u00e9pertoire o\u00f9 r\u00e9side le plugin du gestionnaire de fichiers. Bien que cette restriction emp\u00eache les pirates d&#8217;ex\u00e9cuter des commandes sur des fichiers en dehors du r\u00e9pertoire, les pirates peuvent \u00eatre en mesure d&#8217;infliger des dommages plus importants en t\u00e9l\u00e9chargeant des scripts qui peuvent effectuer des actions sur d&#8217;autres parties d&#8217;un site vuln\u00e9rable.<\/p>\n<p>NinTechNet, une entreprise de s\u00e9curit\u00e9 de sites web \u00e0 Bangkok, en Tha\u00eflande, a \u00e9t\u00e9 l&#8217;une des premi\u00e8res <a href=\"https:\/\/blog.nintechnet.com\/critical-zero-day-vulnerability-fixed-in-wordpress-file-manager-700000-installations\/\" target=\"_blank\" rel=\"noopener noreferrer\">\u00e0 signaler les attaques dans la nature<\/a>. Selon le post, un pirate informatique exploitait la vuln\u00e9rabilit\u00e9 pour t\u00e9l\u00e9charger un script intitul\u00e9 hardfork.php et l&#8217;utilisait ensuite pour injecter du code dans les scripts WordPress \/wp-admin\/admin-ajax.php \u0438 \/wp-includes\/user.php.<\/p>\n<h2>Recouvrement des sites vuln\u00e9rables \u00e0 l&#8217;\u00e9chelle<\/h2>\n<blockquote><p>Dans un courriel, J\u00e9r\u00f4me Bruandet, PDG de NinTechNet, a \u00e9crit<br \/>\nIl est un peu trop t\u00f4t pour en conna\u00eetre l&#8217;impact, car lorsque nous avons pris connaissance de l&#8217;attaque, les pirates informatiques essayaient simplement d&#8217;ouvrir des sites web par des moyens d\u00e9tourn\u00e9s. Cependant, une chose int\u00e9ressante que nous avons remarqu\u00e9e est que les attaquants injectaient du code pour prot\u00e9ger par mot de passe l&#8217;acc\u00e8s au fichier vuln\u00e9rable <code>connector.minimal.php.dist<\/code> afin que d&#8217;autres groupes de pirates ne puissent pas exploiter la vuln\u00e9rabilit\u00e9 sur les sites d\u00e9j\u00e0 infect\u00e9s.<\/p>\n<p>Toutes les commandes peuvent \u00eatre ex\u00e9cut\u00e9es dans le dossier \/lib\/files (cr\u00e9er des dossiers, supprimer des fichiers, etc.), mais le plus important est qu&#8217;ils peuvent \u00e9galement t\u00e9l\u00e9charger des scripts PHP dans ce dossier, puis les ex\u00e9cuter et faire ce qu&#8217;ils veulent sur le blog.<\/p>\n<p>Pour l&#8217;instant, ils t\u00e9l\u00e9chargent &#8220;FilesMan&#8221;, un autre gestionnaire de fichiers souvent utilis\u00e9 par les pirates. Celui-ci est tr\u00e8s obscurci. Dans les prochaines heures et les prochains jours, nous verrons exactement ce qu&#8217;ils feront, car s&#8217;ils ont prot\u00e9g\u00e9 le fichier vuln\u00e9rable par un mot de passe pour emp\u00eacher d&#8217;autres pirates d&#8217;exploiter la vuln\u00e9rabilit\u00e9, il est probable qu&#8217;ils s&#8217;attendent \u00e0 revenir visiter les sites infect\u00e9s.<\/p><\/blockquote>\n<p>Wordfence, une autre entreprise de s\u00e9curit\u00e9 de sites web, a d\u00e9clar\u00e9 dans son <a href=\"https:\/\/www.wordfence.com\/blog\/2020\/09\/700000-wordpress-users-affected-by-zero-day-vulnerability-in-file-manager-plugin\/\" target=\"_blank\" rel=\"noopener noreferrer\">propre article<\/a> qu&#8217;elle avait bloqu\u00e9 plus de 450 000 tentatives d&#8217;exploitation ces derniers jours. Le post indique que les attaquants tentent d&#8217;injecter divers fichiers. Dans certains cas, ces fichiers \u00e9taient vides, le plus souvent dans le but de rechercher des sites vuln\u00e9rables et, en cas de succ\u00e8s, d&#8217;injecter un fichier malveillant par la suite. Les fichiers t\u00e9l\u00e9charg\u00e9s portaient des noms tels que hardfork.php, hardfind.php et x.php.<\/p>\n<p>&#8220;Un tel plugin de gestion de fichiers permettrait \u00e0 un attaquant de manipuler ou de t\u00e9l\u00e9charger les fichiers de son choix directement \u00e0 partir du tableau de bord de WordPress, ce qui lui permettrait d&#8217;augmenter ses privil\u00e8ges une fois dans la zone d&#8217;administration du site&#8221;, a \u00e9crit Chloe Chamberland, chercheur au sein de la soci\u00e9t\u00e9 de s\u00e9curit\u00e9 Wordfence, dans un article publi\u00e9 mardi. &#8220;Par exemple, un attaquant pourrait acc\u00e9der \u00e0 la zone d&#8217;administration du site en utilisant un mot de passe compromis, puis acc\u00e9der \u00e0 ce plugin et t\u00e9l\u00e9charger une coquille web pour faire une nouvelle \u00e9num\u00e9ration du serveur et potentiellement intensifier son attaque en utilisant un autre exploit&#8221;.<\/p>\n<h3 style=\"text-align: center;\">52% de 700 000 = potentiel de dommages<\/h3>\n<p>Le plugin Gestionnaire de fichiers aide les administrateurs \u00e0 g\u00e9rer les fichiers sur les sites utilisant le syst\u00e8me de gestion de contenu WordPress. Le plugin contient un gestionnaire de fichiers suppl\u00e9mentaire appel\u00e9 elFinder, une biblioth\u00e8que open source qui fournit les fonctionnalit\u00e9s de base du plugin, ainsi qu&#8217;une interface utilisateur pour l&#8217;utiliser. La vuln\u00e9rabilit\u00e9 provient de la mani\u00e8re dont le plugin a impl\u00e9ment\u00e9 elFinder.<\/p>\n<div class=\"s__accent\"><div>Pour prot\u00e9ger vos donn\u00e9es contre la surveillance d&#8217;Internet et les garder anonymes &#8211; utilisez <a href=\"https:\/\/freevpnplanet.com\/fr\/data-protection-security\/\">Planet FreeVPN<\/a> sur vos appareils d\u00e8s maintenant!<\/div><\/div>\n<p>&#8220;Le c\u0153ur du probl\u00e8me a commenc\u00e9 avec le plugin du gestionnaire de fichiers qui a renomm\u00e9 l&#8217;extension du fichier <code>connector.minimal.php.dist<\/code> de la biblioth\u00e8que elFinder en .php afin qu&#8217;il puisse \u00eatre ex\u00e9cut\u00e9 directement, m\u00eame si le fichier connector n&#8217;\u00e9tait pas utilis\u00e9 par le gestionnaire de fichiers lui-m\u00eame&#8221;, a expliqu\u00e9 M. Chamberland. &#8220;Ces biblioth\u00e8ques comprennent souvent des fichiers d&#8217;exemple qui ne sont pas destin\u00e9s \u00e0 \u00eatre utilis\u00e9s &#8220;tels quels&#8221; sans ajouter de contr\u00f4les d&#8217;acc\u00e8s, et ce fichier n&#8217;avait aucune restriction d&#8217;acc\u00e8s direct, ce qui signifie que n&#8217;importe qui pouvait y acc\u00e9der. Ce fichier pouvait \u00eatre utilis\u00e9 pour lancer une commande elFinder et \u00e9tait reli\u00e9 au fichier elFinderConnector.class.php&#8221;.<\/p>\n<p>Sal Aguilar, un entrepreneur qui met en place et s\u00e9curise des sites WordPress, <a href=\"https:\/\/twitter.com\/RipeR81\/status\/1300948862727843846\" target=\"_blank\" rel=\"noopener noreferrer\">s&#8217;est rendu sur Twitter<\/a> pour avertir des attaques qu&#8217;il voit.<\/p>\n<div class=\"s__quote\"><div>&#8220;Oh merde !!!&#8221; a-t-il \u00e9crit. &#8220;La vuln\u00e9rabilit\u00e9 du gestionnaire de fichiers WP est S\u00c9RIEUSE. Elle se propage rapidement et je vois des centaines de sites \u00eatre infect\u00e9s. Des logiciels malveillants sont t\u00e9l\u00e9charg\u00e9s sur \/wp-content\/plugins\/wp-file-manager\/lib\/files.&#8221;<\/div><\/div>\n<p style=\"text-align: center;\">La faille de s\u00e9curit\u00e9 se trouve dans les versions du gestionnaire de fichiers allant de 6.0 \u00e0 6.8. <a href=\"https:\/\/wordpress.org\/plugins\/wp-file-manager\/advanced\/\" target=\"_blank\" rel=\"noopener noreferrer\">Les statistiques de WordPress<\/a> montrent qu&#8217;actuellement environ 52 % des installations sont vuln\u00e9rables. Avec plus de la moiti\u00e9 de la base install\u00e9e de File Manager, qui compte 700 000 sites vuln\u00e9rables, le risque de dommages est \u00e9lev\u00e9. Les sites utilisant l&#8217;une de ces versions devraient \u00eatre mis \u00e0 jour vers <a href=\"https:\/\/downloads.wordpress.org\/plugin\/wp-file-manager.zip\" target=\"_blank\" rel=\"noopener noreferrer\">la version 6.9 <\/a>d\u00e8s que possible.<\/p>\n<p style=\"text-align: center;\">\n<script type=\"application\/ld+json\">{\r\n  \"@context\": \"https:\/\/schema.org\",\r\n  \"@type\": \"Article\",\r\n  \"mainEntityOfPage\": {\r\n    \"@type\": \"WebPage\",\r\n    \"@id\": \"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/\"\r\n  },\r\n  \"headline\": \"Les pirates informatiques exploitent les vuln\u00e9rabilit\u00e9s critiques des sites WordPress\",\r\n  \"description\": \"Flaw est dans File Manager, un plugin qui compte plus de 700 000 utilisateurs ; 52% sont concern\u00e9s.\",\r\n  \"image\": \"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-fr-20200903_091431_713535.webp\",  \r\n  \"author\": {\r\n    \"@type\": \"Person\",\r\n    \"name\": \"\u00c9lise Beaudry\"\r\n  },  \r\n  \"publisher\": {\r\n    \"@type\": \"Organization\",\r\n    \"name\": \"Planet FreeVPN\",\r\n    \"logo\": {\r\n      \"@type\": \"ImageObject\",\r\n      \"url\": \"https:\/\/freeplanetvpn.com\/assets\/branding\/planetfreevpn\/website\/logo_squared@2x.jpg\"\r\n    }\r\n  },\r\n  \"datePublished\": \"2020-09-03\",\r\n  \"dateModified\": \"2020-09-03\"\r\n}<\/script>","protected":false},"excerpt":{"rendered":"<p>L&#8217;inconv\u00e9nient est le gestionnaire de fichiers, un plugin qui compte plus de 700 000 utilisateurs, dont 52% souffrent. Les pirates exploitent activement une vuln\u00e9rabilit\u00e9 qui leur permet d&#8217;ex\u00e9cuter des commandes et des scripts malveillants sur des sites web utilisant File Manager, un plugin WordPress avec plus de 700 000 installations actives, ont d\u00e9clar\u00e9 les chercheurs&#8230;<\/p>\n","protected":false},"author":8,"featured_media":34948,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[238],"tags":[],"class_list":["post-18804","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-fr"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Les pirates informatiques exploitent les vuln\u00e9rabilit\u00e9s critiques des sites WordPress \u25b6\ufe0f Planet VPN<\/title>\n<meta name=\"description\" content=\"L&#039;inconv\u00e9nient est le gestionnaire de fichiers, un plugin qui compte plus de 700 000 utilisateurs, dont 52% souffrent.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Les pirates informatiques exploitent les vuln\u00e9rabilit\u00e9s critiques des sites WordPress \u25b6\ufe0f Planet VPN\" \/>\n<meta property=\"og:description\" content=\"L&#039;inconv\u00e9nient est le gestionnaire de fichiers, un plugin qui compte plus de 700 000 utilisateurs, dont 52% souffrent.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/\" \/>\n<meta property=\"og:site_name\" content=\"Planet VPN\" \/>\n<meta property=\"article:published_time\" content=\"2020-09-03T09:15:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-03-28T20:58:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"791\" \/>\n\t<meta property=\"og:image:height\" content=\"439\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Satoshi Naki \u2013 Author of articles\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Satoshi Naki \u2013 Auteur d\u2019articles\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/\",\"url\":\"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/\",\"name\":\"Les pirates informatiques exploitent les vuln\u00e9rabilit\u00e9s critiques des sites WordPress \u25b6\ufe0f Planet VPN\",\"isPartOf\":{\"@id\":\"https:\/\/freevpnplanet.com\/fr\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791.webp\",\"datePublished\":\"2020-09-03T09:15:22+00:00\",\"dateModified\":\"2022-03-28T20:58:55+00:00\",\"author\":{\"@id\":\"https:\/\/freevpnplanet.com\/fr\/#\/schema\/person\/6c5263c6d99110898a1d44d63a1c4fdd\"},\"description\":\"L'inconv\u00e9nient est le gestionnaire de fichiers, un plugin qui compte plus de 700 000 utilisateurs, dont 52% souffrent.\",\"breadcrumb\":{\"@id\":\"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/#breadcrumb\"},\"inLanguage\":\"fr\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr\",\"@id\":\"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/#primaryimage\",\"url\":\"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791.webp\",\"contentUrl\":\"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791.webp\",\"width\":791,\"height\":439},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/freevpnplanet.com\/fr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Les pirates informatiques exploitent les vuln\u00e9rabilit\u00e9s critiques des sites WordPress\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/freevpnplanet.com\/fr\/#website\",\"url\":\"https:\/\/freevpnplanet.com\/fr\/\",\"name\":\"Planet VPN \ud83d\udee1\ufe0f\ud83c\udf10 Free VPN\",\"description\":\"Free VPN\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/freevpnplanet.com\/fr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr\",\"publisher\":{\"@id\":\"https:\/\/freevpnplanet.com\/fr\/#organization\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/freevpnplanet.com\/fr\/#\/schema\/person\/6c5263c6d99110898a1d44d63a1c4fdd\",\"name\":\"Satoshi Naki \u2013 Author of articles\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr\",\"@id\":\"https:\/\/freevpnplanet.com\/fr\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2025\/02\/cropped-writer_enhanced-1-1-96x96.png\",\"contentUrl\":\"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2025\/02\/cropped-writer_enhanced-1-1-96x96.png\",\"caption\":\"Satoshi Naki \u2013 Author of articles\"},\"description\":\"Satoshi is one of the top analysts at Hack The Box: Penetration Testing Labs, specializing in cybersecurity research and analysis. Having a thorough awareness of cyber dangers and ethical hacking, he offers insightful evaluations of attack methods and security flaws. His knowledge helps him to simplify difficult cybersecurity ideas, so they are helpful for both professionals and enthusiasts. Satoshi has vast experience writing on cybersecurity, penetration testing, hackers, and privacy as a cybercrime gonzo journalist. His investigative style gives life to real-life hacking stories, highlighting new dangers and changing strategies. He provides insightful viewpoints on security and digital privacy by delving into the obscure facets of the digital world through in-depth writings and reports.\",\"url\":\"https:\/\/freevpnplanet.com\/fr\/author\/satoshi\/\"},{\"@context\":\"https:\/\/schema.org\/\",\"@type\":\"SoftwareApplication\",\"name\":\"Planet VPN \ud83d\udee1\ufe0f\ud83c\udf10 Free VPN\",\"operatingSystem\":\"Windows, macOS, iOS, Android, Linux, Chrome\",\"applicationCategory\":\"SecurityApplication\",\"offers\":{\"@type\":\"AggregateOffer\",\"priceCurrency\":\"USD\",\"price\":\"0\",\"lowPrice\":\"0\",\"availability\":\"https:\/\/schema.org\/InStock\"},\"aggregateRating\":{\"@type\":\"AggregateRating\",\"ratingValue\":\"4.8\",\"bestRating\":\"5\",\"ratingCount\":\"12476\"}},{\"@type\":\"Organization\",\"@id\":\"https:\/\/freevpnplanet.com\/fr\/#organization\",\"url\":\"https:\/\/freevpnplanet.com\/fr\/\",\"name\":\"Planet VPN \ud83d\udee1\ufe0f\ud83c\udf10 Free VPN\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Les pirates informatiques exploitent les vuln\u00e9rabilit\u00e9s critiques des sites WordPress \u25b6\ufe0f Planet VPN","description":"L'inconv\u00e9nient est le gestionnaire de fichiers, un plugin qui compte plus de 700 000 utilisateurs, dont 52% souffrent.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/","og_locale":"fr_FR","og_type":"article","og_title":"Les pirates informatiques exploitent les vuln\u00e9rabilit\u00e9s critiques des sites WordPress \u25b6\ufe0f Planet VPN","og_description":"L'inconv\u00e9nient est le gestionnaire de fichiers, un plugin qui compte plus de 700 000 utilisateurs, dont 52% souffrent.","og_url":"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/","og_site_name":"Planet VPN","article_published_time":"2020-09-03T09:15:22+00:00","article_modified_time":"2022-03-28T20:58:55+00:00","og_image":[{"width":791,"height":439,"url":"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791.webp","type":"image\/png"}],"author":"Satoshi Naki \u2013 Author of articles","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Satoshi Naki \u2013 Auteur d\u2019articles","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/","url":"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/","name":"Les pirates informatiques exploitent les vuln\u00e9rabilit\u00e9s critiques des sites WordPress \u25b6\ufe0f Planet VPN","isPartOf":{"@id":"https:\/\/freevpnplanet.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/#primaryimage"},"image":{"@id":"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/#primaryimage"},"thumbnailUrl":"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791.webp","datePublished":"2020-09-03T09:15:22+00:00","dateModified":"2022-03-28T20:58:55+00:00","author":{"@id":"https:\/\/freevpnplanet.com\/fr\/#\/schema\/person\/6c5263c6d99110898a1d44d63a1c4fdd"},"description":"L'inconv\u00e9nient est le gestionnaire de fichiers, un plugin qui compte plus de 700 000 utilisateurs, dont 52% souffrent.","breadcrumb":{"@id":"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/#breadcrumb"},"inLanguage":"fr","potentialAction":[{"@type":"ReadAction","target":["https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/"]}]},{"@type":"ImageObject","inLanguage":"fr","@id":"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/#primaryimage","url":"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791.webp","contentUrl":"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2020\/09\/rvpn-25a-20220328_205818_405791.webp","width":791,"height":439},{"@type":"BreadcrumbList","@id":"https:\/\/freevpnplanet.com\/fr\/blog\/les-pirates-informatiques-exploitent-une-faille-critique-affectant-plus-de-350-000-sites-wordpress\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/freevpnplanet.com\/fr\/"},{"@type":"ListItem","position":2,"name":"Les pirates informatiques exploitent les vuln\u00e9rabilit\u00e9s critiques des sites WordPress"}]},{"@type":"WebSite","@id":"https:\/\/freevpnplanet.com\/fr\/#website","url":"https:\/\/freevpnplanet.com\/fr\/","name":"Planet VPN \ud83d\udee1\ufe0f\ud83c\udf10 Free VPN","description":"Free VPN","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/freevpnplanet.com\/fr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr","publisher":{"@id":"https:\/\/freevpnplanet.com\/fr\/#organization"}},{"@type":"Person","@id":"https:\/\/freevpnplanet.com\/fr\/#\/schema\/person\/6c5263c6d99110898a1d44d63a1c4fdd","name":"Satoshi Naki \u2013 Author of articles","image":{"@type":"ImageObject","inLanguage":"fr","@id":"https:\/\/freevpnplanet.com\/fr\/#\/schema\/person\/image\/","url":"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2025\/02\/cropped-writer_enhanced-1-1-96x96.png","contentUrl":"https:\/\/freevpnplanet.com\/wp-content\/uploads\/2025\/02\/cropped-writer_enhanced-1-1-96x96.png","caption":"Satoshi Naki \u2013 Author of articles"},"description":"Satoshi is one of the top analysts at Hack The Box: Penetration Testing Labs, specializing in cybersecurity research and analysis. Having a thorough awareness of cyber dangers and ethical hacking, he offers insightful evaluations of attack methods and security flaws. His knowledge helps him to simplify difficult cybersecurity ideas, so they are helpful for both professionals and enthusiasts. Satoshi has vast experience writing on cybersecurity, penetration testing, hackers, and privacy as a cybercrime gonzo journalist. His investigative style gives life to real-life hacking stories, highlighting new dangers and changing strategies. He provides insightful viewpoints on security and digital privacy by delving into the obscure facets of the digital world through in-depth writings and reports.","url":"https:\/\/freevpnplanet.com\/fr\/author\/satoshi\/"},{"@context":"https:\/\/schema.org\/","@type":"SoftwareApplication","name":"Planet VPN \ud83d\udee1\ufe0f\ud83c\udf10 Free VPN","operatingSystem":"Windows, macOS, iOS, Android, Linux, Chrome","applicationCategory":"SecurityApplication","offers":{"@type":"AggregateOffer","priceCurrency":"USD","price":"0","lowPrice":"0","availability":"https:\/\/schema.org\/InStock"},"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","bestRating":"5","ratingCount":"12476"}},{"@type":"Organization","@id":"https:\/\/freevpnplanet.com\/fr\/#organization","url":"https:\/\/freevpnplanet.com\/fr\/","name":"Planet VPN \ud83d\udee1\ufe0f\ud83c\udf10 Free VPN"}]}},"acf":[],"_links":{"self":[{"href":"https:\/\/freevpnplanet.com\/fr\/wp-json\/wp\/v2\/post\/18804","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freevpnplanet.com\/fr\/wp-json\/wp\/v2\/post"}],"about":[{"href":"https:\/\/freevpnplanet.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freevpnplanet.com\/fr\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/freevpnplanet.com\/fr\/wp-json\/wp\/v2\/comments?post=18804"}],"version-history":[{"count":0,"href":"https:\/\/freevpnplanet.com\/fr\/wp-json\/wp\/v2\/post\/18804\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/freevpnplanet.com\/fr\/wp-json\/wp\/v2\/media\/34948"}],"wp:attachment":[{"href":"https:\/\/freevpnplanet.com\/fr\/wp-json\/wp\/v2\/media?parent=18804"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freevpnplanet.com\/fr\/wp-json\/wp\/v2\/categories?post=18804"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freevpnplanet.com\/fr\/wp-json\/wp\/v2\/tags?post=18804"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}