CVE-2017-16870: SSRF
DISPUTED The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraftajaxhandler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16870?
The severity of CVE-2017-16870 has not been assigned a publicly available CVSS score, but it is a disputed SSRF vulnerability.
How do I fix CVE-2017-16870?
To fix CVE-2017-16870, update the UpdraftPlus plugin to a version beyond 1.13.12 or remove the plugin entirely.
What does CVE-2017-16870 exploit?
CVE-2017-16870 exploits a Server-Side Request Forgery (SSRF) vulnerability in the updraft_ajax_handler function.
Is CVE-2017-16870 a privilege escalation vulnerability?
No, the vendor has reported that CVE-2017-16870 does not cross a privilege boundary.
What affected versions are included in CVE-2017-16870?
CVE-2017-16870 affects the UpdraftPlus plugin versions up to and including 1.13.12.