The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T23:32:46.200Z
Reserved: 2022-02-14T00:00:00
Link: CVE-2022-0591
No data.
Status : Modified
Published: 2022-03-21T19:15:10.937
Modified: 2024-11-21T06:38:58.883
Link: CVE-2022-0591
No data.
OpenCVE Enrichment
No data.
Weaknesses