WooCommerce Plugin Vulnerable to Server-Side Request Forgery
CVE-2024-1758

8.1HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
26 February 2024

Summary

The SuperFaktura WooCommerce plugin for WordPress is susceptible to Server-Side Request Forgery (SSRF), allowing authenticated users with subscriber-level access or higher to exploit this vulnerability. By manipulating the functionality within the wc_sf_url_check function, attackers can initiate web requests to arbitrary locations. This capability poses significant risks, as it could be leveraged to access or modify sensitive internal services, consequently compromising the security of affected environments.

Affected Version(s)

SuperFaktura WooCommerce * <= 1.40.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucio Sá
.