First published: Mon Sep 30 2019(Updated: )
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Themeisle Visualizer | <3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-16932.
The severity of CVE-2019-16932 is critical.
The affected software of CVE-2019-16932 is the Visualizer plugin before version 3.3.1 for WordPress.
CVE-2019-16932 is a blind SSRF vulnerability in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
Yes, you can find references for CVE-2019-16932 at the following links: [link 1](https://nathandavison.com/blog/wordpress-visualizer-plugin-xss-and-ssrf), [link 2](https://wordpress.org/plugins/visualizer/#developers), [link 3](https://wpvulndb.com/vulnerabilities/9892)