Lucene search

K
wpvulndbWpvulndbWPVDB-ID:27C388F4-5C2C-499E-951F-68A298378E6F
HistoryJan 16, 2024 - 12:00 a.m.

Contact Form 7 Extension For Mailchimp <= 0.5.70 - Subscriber+ Server-Side Request Forgery

2024-01-1600:00:00
wpscan.com
11
mailchimp
ssrf
vulnerability
plugin

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

18.1%

Description The plugin is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.5.70. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

18.1%

Related for WPVDB-ID:27C388F4-5C2C-499E-951F-68A298378E6F