Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54193 | The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 via the 'hooks' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 13 Mar 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Platformly
Platformly platform.ly For Woocommerce |
|
| CPEs | cpe:2.3:a:platformly:platform.ly_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Platformly
Platformly platform.ly For Woocommerce |
Fri, 07 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Mar 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 via the 'hooks' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. | |
| Title | Platform.ly for WooCommerce <= 1.1.6 - Unauthenticated Blind Server-Side Request Forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-03-07T17:01:26.988Z
Reserved: 2025-02-24T17:53:43.692Z
Link: CVE-2024-13904
Updated: 2025-03-07T17:00:37.906Z
Status : Analyzed
Published: 2025-03-07T09:15:15.817
Modified: 2025-03-13T17:43:12.470
Link: CVE-2024-13904
No data.
OpenCVE Enrichment
No data.
EUVD