CVE-2024-10705: Multiple Page Generator Plugin – MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrl
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via the 'mpgdownloadfilebylink' function. This makes it possible for authenticated attackers, with editor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10705?
CVE-2024-10705 is rated as a critical severity vulnerability due to its potential for Server-Side Request Forgery exploitation.
Who is affected by CVE-2024-10705?
CVE-2024-10705 affects users of the Multiple Page Generator Plugin for WordPress up to version 4.0.5.
How do I fix CVE-2024-10705?
To fix CVE-2024-10705, update the Multiple Page Generator Plugin to the latest version beyond 4.0.5.
What type of attack does CVE-2024-10705 facilitate?
CVE-2024-10705 facilitates Server-Side Request Forgery (SSRF) attacks for authenticated users with editor-level access and above.
Is CVE-2024-10705 present in older versions of the MPG plugin?
Yes, CVE-2024-10705 is present in all versions of the Multiple Page Generator Plugin for WordPress up to and including 4.0.5.