CVE-2024-13905

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Feb 27, 2025
Updated: Mar 12, 2025
CWE ID 918

Summary

CVE-2024-13905 is a Server-Side Request Forgery (SSRF) vulnerability affecting the OneStore Sites plugin for WordPress. The flaw, found in the class-export.php file, allows unauthenticated attackers to make web requests from the vulnerable application to arbitrary internal locations. This vulnerability can be exploited to access and modify sensitive information from connected internal services, posing a significant security risk. All versions up to and including 0.1.1 are reportedly affected. It is crucial for WordPress users to update their OneStore Sites plugin to the latest version as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Onestore Sites Plugin

Affected Vendors

  • WordPress