CVE-2024-0628 Information
Feb 08, 2024
cve
Description
The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers with administrator-level access and above to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Reference
https://www.wordfence.com/threat-intel/vulnerabilities/id/2154383e-eabb-4964-8991-423dd68d5efb?source=cve https://plugins.trac.wordpress.org/changeset/3029525/wp-rss-aggregator
Share on: