ZeroHour

CVE-2023-1938

PoC
CVSS 3.1
8.8 high
EPSS
8%p95
Published
()
Modified
Description

The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate user input before using it in the wp_remote_get() function, leading to a Blind SSRF issue

Vendors
wpfastestcache
Products
wp fastest cache
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.