CVE-2022-3247: Blog2Social < 6.9.10 - Subscriber+ SSRF
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3247?
The severity of CVE-2022-3247 is medium with a severity value of 6.5.
Which version of the Blog2Social plugin is affected by CVE-2022-3247?
The Blog2Social plugin version up to 6.9.10 is affected by CVE-2022-3247.
What is the vulnerability description of CVE-2022-3247?
CVE-2022-3247 is a vulnerability in the Blog2Social WordPress plugin that allows authenticated users to perform SSRF attacks due to the lack of authorization in an AJAX action and a failure to ensure the URL is an external one.
How can the CVE-2022-3247 vulnerability be exploited?
Authenticated users, such as subscribers, can exploit the CVE-2022-3247 vulnerability by performing SSRF attacks using the Blog2Social plugin.
Is there a fix for CVE-2022-3247?
Yes, upgrading the Blog2Social plugin to version 6.9.10 or above fixes CVE-2022-3247.