WooCommerce Plugin Vulnerable to Server-Side Request Forgery
CVE-2024-1758
8.1HIGH
What is CVE-2024-1758?
The SuperFaktura WooCommerce plugin for WordPress is susceptible to Server-Side Request Forgery (SSRF), allowing authenticated users with subscriber-level access or higher to exploit this vulnerability. By manipulating the functionality within the wc_sf_url_check function, attackers can initiate web requests to arbitrary locations. This capability poses significant risks, as it could be leveraged to access or modify sensitive internal services, consequently compromising the security of affected environments.
Affected Version(s)
SuperFaktura WooCommerce * <= 1.40.3