CVE-2024-13845: Gravity Forms WebHooks <= 1.6.0 - Authenticated (Admin+) Server-Side Request Forgery via Webhook
The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.0 via the 'processfeed' method of the GFWebhooks class This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13845?
CVE-2024-13845 has a critical severity rating due to its potential for Server-Side Request Forgery exploits.
Who is affected by CVE-2024-13845?
CVE-2024-13845 affects authenticated users with Administrator-level access using versions of the Gravity Forms WebHooks plugin up to 1.6.0.
How do I fix CVE-2024-13845?
To fix CVE-2024-13845, upgrade the Gravity Forms WebHooks plugin to version 1.7.0 or higher.
What type of vulnerability is CVE-2024-13845?
CVE-2024-13845 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
What versions of the Gravity Forms WebHooks plugin are impacted by CVE-2024-13845?
All versions of the Gravity Forms WebHooks plugin up to and including 1.6.0 are impacted by CVE-2024-13845.