Lucene search

K
wpvulndbWpvulndbWPVDB-ID:D444A693-7F2B-451E-8004-B40B8C1C64B0
HistoryFeb 06, 2024 - 12:00 a.m.

TablePress < 2.2.5 - Authenticated(Author+) Server Side Request Forgery(SSRF) via _get_import_files

2024-02-0600:00:00
wpscan.com
13
tablepress
wordpress
ssrf
server-side request forgery
authenticated
author+
_get_import_files

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

18.1%

Description The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to and including 2.2.4 via the ‘_get_import_files’ function. This makes it possible for authenticated attackers, with author access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

18.1%

Related for WPVDB-ID:D444A693-7F2B-451E-8004-B40B8C1C64B0