PT-2013-2177 · WordPress · Wordpress

Gennady Kovshenin

+1

·

Published

2013-07-08

·

Updated

2013-07-08

·

CVE-2013-0235

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 3.5.1
Description The issue allows remote attackers to send HTTP requests to intranet servers and conduct port-scanning attacks by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue. This affects the XMLRPC API.
Recommendations For versions prior to 3.5.1, update to version 3.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the XMLRPC API until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2013-0235

Affected Products

Wordpress