CVE-2023-1895
09.06.2023, 06:15
The Getwid Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.Enginsight
Vendor | Product | Version |
---|---|---|
motopress | getwid | 𝑥 ≤ 1.8.3 |
𝑥
= Vulnerable software versions
References