Server-Side Request Forgery Vulnerability in Compact WP Audio Player by Tips and Tricks HQ
CVE-2024-56279

6.4MEDIUM

Key Information:

Vendor
Tips And Tricks Hq
Status
Compact WP Audio Player
Vendor
CVE Published:
7 January 2025

Summary

A vulnerability has been identified in the Compact WP Audio Player plugin developed by Tips and Tricks HQ. This issue involves Server-Side Request Forgery (SSRF), allowing attackers to send unauthorized requests from the server. This vulnerability affects versions of the plugin up to 1.9.14 and poses a significant risk by enabling potential exploitation that could compromise the integrity of the server and its resources.

Affected Version(s)

Compact WP Audio Player <= 1.9.14

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.