CVE-2013-2199

WordPress < 3.5.2 - Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_confirm
http://wordpress.org/news/2013/06/wordpress-3-5-2/
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2718
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=976784
Product x_refsource_confirm
http://codex.wordpress.org/Version_3.5.2

Scores

EPSS 0.0083
EPSS Percentile 74.8%

Details

CWE
CWE-264
Status published
Products (49)
wordpress/wordpress 0.71
wordpress/wordpress 1.0
wordpress/wordpress 1.0.1
wordpress/wordpress 1.0.2
wordpress/wordpress 1.1.1
wordpress/wordpress 1.2
wordpress/wordpress 1.2.1
wordpress/wordpress 1.2.2
wordpress/wordpress 1.2.3
wordpress/wordpress 1.2.4
... and 39 more
Published Jul 08, 2013
Tracked Since Feb 18, 2026