CVE-2013-0235
Wordpress < 3.5.0 - SSRF
Title source: ruleDescription
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.
Exploits (1)
metasploit
SCANNER
by Thomas McCarthy · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/wordpress_pingback_access.rb
References (5)
Scores
EPSS
0.5836
EPSS Percentile
98.2%
Details
Status
published
Products (49)
wordpress/wordpress
0.71
wordpress/wordpress
1.0
wordpress/wordpress
1.0.1
wordpress/wordpress
1.0.2
wordpress/wordpress
1.1.1
wordpress/wordpress
1.2
wordpress/wordpress
1.2.1
wordpress/wordpress
1.2.2
wordpress/wordpress
1.2.3
wordpress/wordpress
1.2.4
... and 39 more
Published
Jul 08, 2013
Tracked Since
Feb 18, 2026