UpdraftCentral Dashboard 0.8.23 - Server-Side Request Forgery
highThe UpdraftCentral Dashboard plugin 0.8.23 for WordPress is vulnerable to Server-Side Request Forgery via the font parameter in the load_font action. It allows an unauthenticated attacker to make a request to any internal and external server.
- CVSS:
- 8.3
- Affected:
- 0.8.23 – 0.8.23
- Fixed in:
- 0.8.24
- Disclosed:
- Dec 6, 2022