The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-01-10T20:55:53.771Z
Reserved: 2023-04-25T19:27:58.424Z
Link: CVE-2023-2287

Updated: 2024-08-02T06:19:14.853Z

Status : Modified
Published: 2023-05-30T08:15:10.157
Modified: 2025-01-10T21:15:11.440
Link: CVE-2023-2287

No data.