CVE-2023-5877: affiliate-toolkit < 3.4.3 - Unauthenticated SSRF
The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkpimagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5877?
CVE-2023-5877 has a medium severity rating due to its potential for unauthorized access and exploitation.
How do I fix CVE-2023-5877?
To fix CVE-2023-5877, update the affiliate-toolkit WordPress plugin to version 3.4.3 or later.
What vulnerabilities are associated with CVE-2023-5877?
CVE-2023-5877 allows unauthenticated visitors to make requests to arbitrary URLs, which could lead to privacy breaches.
Who is affected by CVE-2023-5877?
CVE-2023-5877 affects users of the affiliate-toolkit WordPress plugin versions prior to 3.4.3.
Is there a risk of data exposure with CVE-2023-5877?
Yes, CVE-2023-5877 poses a risk of data exposure as it allows access to internal network addresses.