The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-06-27T08:59:05

Updated: 2022-06-27T08:59:05

Reserved: 2022-06-02T00:00:00


Link: CVE-2022-1977

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-06-27T09:15:10.527

Modified: 2023-06-07T15:06:55.573


Link: CVE-2022-1977

JSON object: View

cve-icon Redhat Information

No data.

CWE