Server-Side Request Forgery in Video Downloader for TikTok Plugin for WordPress
CVE-2020-24142
9.8CRITICAL
What is CVE-2020-24142?
The Video Downloader for TikTok plugin version 1.3 for WordPress contains a server-side request forgery (SSRF) vulnerability. This flaw allows an attacker to craft specific requests that can be sent from the back-end server of a vulnerable web application. The exploitation of this vulnerability can facilitate the discovery of open ports, uncover local network hosts, and potentially execute commands on services, posing a significant security risk to WordPress installations utilizing this plugin.