SSRF Attack Vulnerability in Popup Builder WordPress Plugin
CVE-2023-6294
Key Information:
- Vendor
- Wordpress
- Status
- Vendor
- CVE Published:
- 12 February 2024
Badges
Summary
The Popup Builder WordPress plugin prior to version 4.2.6 has a significant security flaw that arises from inadequate validation of parameters during requests. This vulnerability can be exploited by users with administrative privileges within Multisite WordPress environments, potentially allowing for Server-Side Request Forgery (SSRF) attacks. Such attacks can lead to unauthorized access to internal resources or sensitive data on the server, thereby posing a serious risk to the security of the affected WordPress installations.
Affected Version(s)
Popup Builder 0 < 4.2.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved