CVE-2024-4260: CoBlocks < 3.1.12 - Contributor+ SSRF
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4260?
CVE-2024-4260 is classified as a high severity vulnerability due to its potential for SSRF attacks.
How do I fix CVE-2024-4260?
To fix CVE-2024-4260, update the Page Builder Gutenberg Blocks plugin to version 3.1.12 or later.
What types of attacks can CVE-2024-4260 facilitate?
CVE-2024-4260 can facilitate Server-Side Request Forgery (SSRF) attacks by allowing high privilege users to ping arbitrary hosts.
Who is affected by CVE-2024-4260?
Users and administrators of the Page Builder Gutenberg Blocks WordPress plugin prior to version 3.1.12 are affected by CVE-2024-4260.
What are the potential risks of CVE-2024-4260?
The potential risks of CVE-2024-4260 include unauthorized server access and data leakage through SSRF vulnerabilities.