Description
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected products
- Unknown / Kirki0 – 6.0.12
Exploits & proofs of concept
- nucleiWordPress Kirki < 6.0.12 - Server-Side Request Forgeryby 0x_Akoko
Updated 20m ago · 8 sources