CVE-2022-1398
MEDIUM 6.5EPSS 3.1%
The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are external medias, which could allow any authenticated users, such as subscriber to perform blind SSRF attacks
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 4.0 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N - EPSS
- 3.05% chance of exploitation in the next 30 days, 87th percentile
- Nuclei
- medium · CWE-918
- Published
- 2022-05-16
- Updated
- 2024-08-03