Server-Side Request Forgery Vulnerability in Compact WP Audio Player by Tips and Tricks HQ
CVE-2024-56279
6.4MEDIUM
Key Information:
- Vendor
- Tips And Tricks Hq
- Status
- Compact WP Audio Player
- Vendor
- CVE Published:
- 7 January 2025
Summary
A vulnerability has been identified in the Compact WP Audio Player plugin developed by Tips and Tricks HQ. This issue involves Server-Side Request Forgery (SSRF), allowing attackers to send unauthorized requests from the server. This vulnerability affects versions of the plugin up to 1.9.14 and poses a significant risk by enabling potential exploitation that could compromise the integrity of the server and its resources.
Affected Version(s)
Compact WP Audio Player <= 1.9.14
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
theviper17 (Patchstack Alliance)