CVE-2024-13879: Stream <= 4.0.2 - Authenticated (Admin+) Server-Side Request Forgery
The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2 due to insufficient validation on the webhook feature. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13879?
CVE-2024-13879 is a high-severity vulnerability due to its potential for Server-Side Request Forgery.
Who is affected by CVE-2024-13879?
Authenticated users with administrator-level access and above are at risk from CVE-2024-13879.
How do I fix CVE-2024-13879?
To mitigate CVE-2024-13879, update the Stream plugin for WordPress to version 4.0.3 or later.
What type of vulnerability is CVE-2024-13879?
CVE-2024-13879 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
What versions of the Stream plugin are affected by CVE-2024-13879?
CVE-2024-13879 affects all versions of the Stream plugin for WordPress up to and including version 4.0.2.