CVE-2019-16932

CRITICAL EXPLOITED NUCLEI

Visualizer < 3.3.1 - Server-Side Request Forgery via wp-json/visualizer/v1/upload-data

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-16932 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

Nuclei Templates (1)

Visualizer <3.3.1 - Blind Server-Side Request Forgery
CRITICALby akincibor

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/9892
Product, Third Party Advisory x_refsource_misc
https://wordpress.org/plugins/visualizer/#developers
Exploit, Third Party Advisory x_refsource_misc
https://nathandavison.com/blog/wordpress-visualizer-plugin-xss-and-ssrf

Scores

CVSS v3 10.0
EPSS 0.3753
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Details

VulnCheck KEV 2023-12-11
CWE
CWE-918
Status published
Products (1)
themeisle/visualizer < 3.3.1
Published Sep 30, 2019
Tracked Since Feb 18, 2026