PT-2022-19415 · WordPress · Craw Data Wordpress Plugin

Dhanesh Sivasamy

·

Published

2022-09-16

·

Updated

2025-06-03

·

CVE-2022-2912

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Craw Data WordPress plugin versions through 1.0.0
Description The issue is related to the lack of nonce checks in the Craw Data WordPress plugin, which could allow attackers to make a logged-in admin change the url value, performing unwanted crawls on third-party sites, also known as Server-Side Request Forgery (SSRF).
Recommendations For Craw Data WordPress plugin versions through 1.0.0, consider disabling the plugin until a patch is available to prevent potential SSRF attacks. Restrict access to the plugin's settings to minimize the risk of exploitation. Avoid using the url value in the affected plugin until the issue is resolved.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-2912

Affected Products

Craw Data Wordpress Plugin