Server-Side Request Forgery in Zapier for WordPress Plugin
CVE-2024-13411
What is CVE-2024-13411?
The Zapier for WordPress plugin allows authenticated users with Subscriber-level permissions and above to exploit a Server-Side Request Forgery vulnerability in all versions up to and including 1.5.1. This flaw resides in the updated_user() function, enabling attackers to initiate requests to arbitrary endpoints from the affected web application. Consequently, this could potentially allow the attacker to interact with and manipulate internal services, leading to unauthorized access to sensitive information or disruption of service.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Zapier for WordPress * <= 1.5.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved