CVE-2023-1938
PoC —CVSS 3.1
8.8 high
EPSS
8%p95
Published
()
Modified
Description
The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate user input before using it in the wp_remote_get() function, leading to a Blind SSRF issue
- Vendors
- wpfastestcache
- Products
- wp fastest cache
- Ecosystems
- WordPress
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.