CVE-2024-1978
Dashboard / Vulnerabilities / CVE-2024-1978
CVE-2024-1978
Summary: Friends <= 2.8.5 - Authenticated (Admin+) Blind Server-Side Request Forgery
Details: The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.5 via the discover_available_feeds function. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
References: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3036987%40friends&new=3036987%40friends&sfp_email=&sfph_mail=, https://www.wordfence.com/threat-intel/vulnerabilities/id/72e1fbce-86ae-4518-a613-7c322193acf4?source=cve, https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1978.json, https://nvd.nist.gov/vuln/detail/CVE-2024-1978, https://github.com/akirk/friends/pull/290
Affected packages
Package
Name:
Purl:
