External Media without Import <= 1.1.2 - Authenticated (Subscriber+) Blind Server-Side Request Forgery
medium
The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are external medias, which could allow any authenticated users, such as subscriber to perform blind SSRF attacks
- CVSS:
- 6.4
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 19, 2022
CVE-2022-1398 on NVD →
External Media without Import < 1.0.0 - Reflected Cross-Site Scripting
medium
The External Media without Import plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error' parameter in versions up to 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 1.0.0
- Fixed in:
- 1.0.0
- Disclosed:
- Oct 15, 2017
CVE-2017-20183 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database