First published: Wed Apr 24 2024(Updated: )
The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImportWP | <2.13.1 | |
WordPress Import WP | <2.13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-7253 is considered a critical vulnerability due to its potential for server-side request forgery (SSRF) attacks.
To fix CVE-2023-7253, upgrade the Import WP WordPress plugin to version 2.13.1 or later.
CVE-2023-7253 affects WordPress sites using the Import WP plugin prior to version 2.13.1.
CVE-2023-7253 can lead to unauthorized access to internal network resources through SSRF attacks.
While CVE-2023-7253 poses risks in multisite configurations, any WordPress site using an affected version may be at risk.