CVE-2022-3247 Information
Oct 26, 2022
cve
Description
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action and does not ensure that the URL to make a request to is an external one. As a result any authenticated users such as subscriber could perform SSRF attacks
Reference
https://wpscan.com/vulnerability/ee312f22-ca58-451d-a1cb-3f78a6e5ecaf
Share on: