PT-2022-13286 · WordPress · Formcraft
Brandon James Roldan
+1
·
Published
2022-03-21
·
Updated
2023-09-07
·
CVE-2022-0591
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FormCraft WordPress plugin versions prior to 3.8.28
Description
The issue concerns the FormCraft WordPress plugin, where the URL parameter in the formcraft3 get AJAX action is not properly validated, leading to Server-Side Request Forgery (SSRF) issues. These issues can be exploited by unauthenticated users.
Recommendations
For versions prior to 3.8.28, update to version 3.8.28 or later to resolve the issue. As a temporary workaround, consider restricting access to the formcraft3 get AJAX action to minimize the risk of exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Formcraft