PT-2025-33892 · WordPress · Wp Crontrol
Jonas Benjamin Friedli
·
Published
2025-08-19
·
Updated
2025-08-22
·
CVE-2025-8678
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
WP Crontrol versions 1.17.0 through 1.19.1
Description:
The WP Crontrol plugin for WordPress is vulnerable to Server-Side Request Forgery via the
wp remote request() function. This allows authenticated attackers with Administrator-level access and above to make web requests to arbitrary locations originating from the web application, potentially allowing them to query and modify information from internal services.Recommendations:
WP Crontrol versions 1.17.0 through 1.19.1 should be updated to version 1.19.2 or later.
If an immediate update is not possible, remove any Administrator-level users who are not fully trusted.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Crontrol