Craw Data <= 1.0.0 - Server Side Request Forgery
highThe Craw Data plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.0.0 due to missing nonce checks, which could allow attackers to make a logged in admin change the URL value resulting in unwanted crawls on third-party sites.
- CVSS:
- 7.4
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 19, 2022