The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/69f33e20-8ff4-491c-8f37-a4eadd4ea8cf/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/69f33e20-8ff4-491c-8f37-a4eadd4ea8cf/ | Exploit Third Party Advisory |
Configurations
History
16 May 2025, 12:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/69f33e20-8ff4-491c-8f37-a4eadd4ea8cf/ - Exploit, Third Party Advisory | |
First Time |
Godaddy coblocks
Godaddy |
|
CWE | CWE-918 | |
CPE | cpe:2.3:a:godaddy:coblocks:*:*:*:*:*:wordpress:*:* |
23 Jul 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-23 06:15
Updated : 2025-05-16 12:44
NVD link : CVE-2024-4260
Mitre link : CVE-2024-4260
JSON object : View
Products Affected
godaddy
- coblocks
CWE
CWE-918
Server-Side Request Forgery (SSRF)