CVE-2023-7253

The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.
CVSS

No CVSS.

Configurations

No configuration.

History

24 Apr 2024, 13:39

Type Values Removed Values Added
Summary
  • (es) El complemento Import WP WordPress anterior a 2.13.1 no impide que los usuarios con funciĆ³n de administrador hagan ping al realizar ataques SSRF, lo que puede ser un problema en configuraciones multisitio.

24 Apr 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-24 05:15

Updated : 2024-04-24 13:39


NVD link : CVE-2023-7253

Mitre link : CVE-2023-7253

CVE.ORG link : CVE-2023-7253


JSON object : View

Products Affected

No product.

CWE

No CWE.