CVE-2013-0235: SSRF
From WordPress upstream v3.5.1 advisory [1]: A server-side request forgery vulnerability and remote port scanning using pingbacks. This vulnerability, which could potentially be used to expose information and compromise a site, affects all previous WordPress versions. This was fixed by the WordPress security team. We’d like to thank security researchers Gennady Kovshenin and Ryan Dewhurst for reviewing our work.
References: [1] http://wordpress.org/news/2013/01/wordpress-3-5-1/ [2] http://www.openwall.com/lists/oss-security/2013/01/25/7
Other sources
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0235?
CVE-2013-0235 is classified as a critical server-side request forgery vulnerability that can expose sensitive information.
How do I fix CVE-2013-0235?
To fix CVE-2013-0235, you should update your WordPress installation to version 3.5.1 or later.
What versions of WordPress are affected by CVE-2013-0235?
CVE-2013-0235 affects all WordPress versions prior to 3.5.1.
Can CVE-2013-0235 cause data leakage?
Yes, CVE-2013-0235 can be exploited to leak sensitive information and compromise website security.
Is there a known exploit for CVE-2013-0235?
Yes, there are known exploits that leverage CVE-2013-0235 for unauthorized information exposure and remote port scanning.