WooCommerce Plugin Vulnerable to Server-Side Request Forgery
CVE-2024-1758
8.1HIGH
Summary
The SuperFaktura WooCommerce plugin for WordPress is susceptible to Server-Side Request Forgery (SSRF), allowing authenticated users with subscriber-level access or higher to exploit this vulnerability. By manipulating the functionality within the wc_sf_url_check function, attackers can initiate web requests to arbitrary locations. This capability poses significant risks, as it could be leveraged to access or modify sensitive internal services, consequently compromising the security of affected environments.
Affected Version(s)
SuperFaktura WooCommerce * <= 1.40.3
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lucio Sá