jRSS Widget [jrss-widget] <= 1.2 (closed)
unknown
[en] Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress allows remote attackers to trigger outbound requests and enumerate open ports via the url parameter.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Dec 5, 2014
CVE-2014-9292 on NVD →
jRSS Widget <= 1.2 - Server-Side Request Forgery
high
Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress allows remote attackers to trigger outbound requests and enumerate open ports via the url parameter.
- CVSS:
- 7.5
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- May 28, 2014
CVE-2014-9292 on NVD →
jRSS Widget [jrss-widget] < 1.1.2 (closed)
unknown
This jRSS Widget plugin is prone to an information-disclosure vulnerability. Application fails to validate user-supplied data. Because of this issue, an attacker can view local files in the context of the affected application. In that way, the attacker obtains sensitive information. Other attacks are also possible.
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Nov 8, 2010
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database