Lucene search

K
wpvulndbWpvulndbWPVDB-ID:7FE83E4B-7574-42B3-840F-A80BADEA2A18
HistoryNov 13, 2023 - 12:00 a.m.

PowerPress Podcasting < 11.0.7 - Contributor+ SSRF

2023-11-1300:00:00
wpscan.com
9
powerpress podcasting
ssrf
vulnerability
ajax action
contributor
role
software

AI Score

7

Confidence

High

EPSS

0.001

Percentile

18.1%

Description The plugin does not validate a parameter before making a request to it via the powerpress_media_info AJAX action, which could allow Contributor and above role to perform SSRF attacks

AI Score

7

Confidence

High

EPSS

0.001

Percentile

18.1%

Related for WPVDB-ID:7FE83E4B-7574-42B3-840F-A80BADEA2A18