CVE-2024-13905
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2024-13905 is a Server-Side Request Forgery (SSRF) vulnerability affecting the OneStore Sites plugin for WordPress. The flaw, found in the class-export.php file, allows unauthenticated attackers to make web requests from the vulnerable application to arbitrary internal locations. This vulnerability can be exploited to access and modify sensitive information from connected internal services, posing a significant security risk. All versions up to and including 0.1.1 are reportedly affected. It is crucial for WordPress users to update their OneStore Sites plugin to the latest version as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Onestore Sites Plugin
Affected Vendors
- WordPress