Server-Side Request Forgery in UpdraftPlus WordPress Plugin
CVE-2017-16870
8.1HIGH
What is CVE-2017-16870?
The UpdraftPlus plugin for WordPress, specifically version 1.13.12, contains a Server-Side Request Forgery vulnerability in the updraft_ajax_handler function located in the admin.php file. This vulnerability arises when handling an httpget subaction. Although the vendor reports that this does not cross a privilege boundary, it still poses a security risk, allowing unauthorized requests to be made from the server. It's crucial for users of the UpdraftPlus plugin to be aware of this issue and apply necessary updates.