PT-2025-8911 · WordPress · Onestore Sites

Francesco Carlucci

·

Published

2025-02-27

·

Updated

2025-03-11

·

CVE-2024-13905

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OneStore Sites plugin for WordPress versions prior to 0.1.2
Description The issue allows unauthenticated attackers to make web requests to arbitrary locations originating from the web application. This can be used to query and modify information from internal services. The vulnerability is related to Server-Side Request Forgery via the class-export.php file.
Recommendations For versions prior to 0.1.2, update to version 0.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the class-export.php file to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13905

Affected Products

Onestore Sites