Lucene search

K
wpvulndbWpvulndbWPVDB-ID:09FE7C94-E0FC-4DE2-BD8F-CF2D3183751C
HistoryDec 08, 2023 - 12:00 a.m.

SpeedyCache < 1.1.3 - Authenticated (Subscriber+) Server-Side Request Forgery

2023-12-0800:00:00
wpscan.com
9
speedycache
authenticated
ssrf
wordpress
vulnerability
server-side request forgery
1.1.3

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

14.0%

Description The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.2 via the speedycache_create_test_cache() function. This makes it possible for authenticated attackers, subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

14.0%

Related for WPVDB-ID:09FE7C94-E0FC-4DE2-BD8F-CF2D3183751C