Description
Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticated server-side request forgery vulnerability that allows Author-level users to fetch internal HTTP resources. Attackers can exploit insecure URL fetching and file write operations to retrieve sensitive internal data and store it in web-accessible upload directories.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
Any version before 1.7
Credits
4lec4st
References
wordpress.org/plugins/featured-image-from-content/
www.vulncheck.com/...ontent-authenticated-ssrf-via-save-post