PT-2022-13286 · WordPress · Formcraft

Brandon James Roldan

+1

·

Published

2022-03-21

·

Updated

2023-09-07

·

CVE-2022-0591

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions FormCraft WordPress plugin versions prior to 3.8.28
Description The issue concerns the FormCraft WordPress plugin, where the URL parameter in the formcraft3 get AJAX action is not properly validated, leading to Server-Side Request Forgery (SSRF) issues. These issues can be exploited by unauthenticated users.
Recommendations For versions prior to 3.8.28, update to version 3.8.28 or later to resolve the issue. As a temporary workaround, consider restricting access to the formcraft3 get AJAX action to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-0591

Affected Products

Formcraft