VDB
CVE-2022-3708
CVE-2022-3708
PUBLISHED
CVSS 9.600000381469727 CRITICAL
The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This made it possible for authenticated users to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
EPSS 0.79% · 54.8th percentile
Risk Scores
CVSS 3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
EPSS Score
0.79%
54.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| web_stories | 0 | |
| Web Stories | * |
Timeline
- Oct 28, 2022 CVE Published
- Oct 29, 2022 EPSS Score
- Dec 12, 2022 EPSS Score
- Jan 25, 2023 EPSS Score
- Mar 10, 2023 EPSS Score
- Apr 23, 2023 EPSS Score
- Jun 5, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 1, 2023 EPSS Score
- Oct 15, 2023 EPSS Score
- Jan 11, 2024 EPSS Score
- Feb 24, 2024 EPSS Score
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/7817a840-325a-4709-8374-84bb32d98d0e?source=cve url
- https://wordpress.org/plugins/web-stories url
- https://github.com/GoogleForCreators/web-stories-wp/compare/v1.24.0...v1.25.0 url
- https://github.com/GoogleForCreators/web-stories-wp/commit/3ad2099f95155d658624ffac2e34ce0da739e34b url
- https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-3708 url
- https://nvd.nist.gov/vuln/detail/CVE-2022-3708 advisory