Server-Side Request Forgery in Zapier for WordPress Plugin
CVE-2024-13411

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 March 2025

What is CVE-2024-13411?

The Zapier for WordPress plugin allows authenticated users with Subscriber-level permissions and above to exploit a Server-Side Request Forgery vulnerability in all versions up to and including 1.5.1. This flaw resides in the updated_user() function, enabling attackers to initiate requests to arbitrary endpoints from the affected web application. Consequently, this could potentially allow the attacker to interact with and manipulate internal services, leading to unauthorized access to sensitive information or disruption of service.

Affected Version(s)

Zapier for WordPress * <= 1.5.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khayal Farzaliyev
.