Server-Side Request Forgery Vulnerability in Stream Plugin for WordPress
CVE-2024-13879
5.5MEDIUM
What is CVE-2024-13879?
The Stream plugin for WordPress contains a vulnerability that enables authenticated attackers with administrator-level access to exploit insufficient validation in its webhook feature. This flaw allows them to send web requests to arbitrary locations, which may lead to the unauthorized querying or modification of sensitive information from internal services, potentially compromising the overall security of the application.
Affected Version(s)
Stream * <= 4.0.2