The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.1.1 via the class-export.php file. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
History

Wed, 12 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:sainwp:onestore_sites:*:*:*:*:*:*:wordpress:*:* cpe:2.3:a:sainwp:onestore_sites:*:*:*:*:*:wordpress:*:*

Wed, 12 Mar 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Sainwp
Sainwp onestore Sites
CPEs cpe:2.3:sainwp:onestore_sites:*:*:*:*:*:*:wordpress:*:* cpe:2.3:a:sainwp:onestore_sites:*:*:*:*:*:*:wordpress:*:*
Vendors & Products Onestore Sites
Onestore Sites *
Sainwp
Sainwp onestore Sites

Tue, 11 Mar 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Onestore Sites
Onestore Sites *
CPEs cpe:2.3:sainwp:onestore_sites:*:*:*:*:*:*:wordpress:*:*
Vendors & Products Onestore Sites
Onestore Sites *

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Feb 2025 04:30:00 +0000

Type Values Removed Values Added
Description The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.1.1 via the class-export.php file. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Title OneStore Sites <= 0.1.1 - Unauthenticated Blind Server-Side Request Forgery
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-27T14:46:14.196Z

Reserved: 2025-02-24T18:06:40.517Z

Link: CVE-2024-13905

cve-icon Vulnrichment

Updated: 2025-02-27T14:46:10.306Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-27T05:15:13.610

Modified: 2025-03-12T17:47:03.400

Link: CVE-2024-13905

cve-icon Redhat

No data.