PT-2023-18742 · Themeisle · Orbit Fox

·

CVE-2023-2287

·

Publicado

2023-05-30

·

Atualizado

2025-01-10

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Orbit Fox by ThemeIsle WordPress plugin versions prior to 2.10.24
Description The issue allows users to specify arbitrary URLs for the stock photo import feature, leading to a server-side request forgery. This enables users to force the server to access any URL of their choosing.
Recommendations For versions prior to 2.10.24, update to version 2.10.24 or later to resolve the issue. As a temporary workaround, consider restricting access to the stock photo import feature until the update is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-2287

Produtos afetados

Orbit Fox