VDB

CVE-2022-3708

CVE-2022-3708 PUBLISHED CVSS 9.600000381469727 CRITICAL

The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This made it possible for authenticated users to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

EPSS 0.79% · 54.8th percentile

Risk Scores

CVSS 3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
EPSS Score
0.79%
54.8th percentile

Affected Products

VendorProductVersions
googleweb_stories0
googleWeb Stories*

Timeline

  • Oct 28, 2022 CVE Published
  • Oct 29, 2022 EPSS Score
  • Dec 12, 2022 EPSS Score
  • Jan 25, 2023 EPSS Score
  • Mar 10, 2023 EPSS Score
  • Apr 23, 2023 EPSS Score
  • Jun 5, 2023 EPSS Score
  • Jul 19, 2023 EPSS Score
  • Sep 1, 2023 EPSS Score
  • Oct 15, 2023 EPSS Score
  • Jan 11, 2024 EPSS Score
  • Feb 24, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›