Record summary

CVE-2022-1398 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are external medias, which could allow any authenticated users, such as subscriber to perform blind SSRF attacks

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

External Media without Import

CVE List1.1.2 to ≤ 1.1.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMExternal Media without Import <=1.1.2 - Authenticated Blind Server-Side Request ForgeryCVSS 6.5

WordPress External Media without Import plugin through 1.1.2 is susceptible to authenticated blind server-side request forgery. The plugin has no authorization and does not ensure that media added via URLs are external media, which can allow any authenticated users, including subscribers, to obtain sensitive information, modify data, and/or execute unauthorized administrative operations.

Impact

Successful exploitation of this vulnerability could allow an attacker to bypass network restrictions, access internal resources, and potentially perform further attacks.

Remediation

Upgrade to External Media without Import plugin version 1.1.2 or later.

WeaknessesCWE-918
Authorstheamanrawat
Template tagscve2022cvessrfwordpresswp-pluginwpwpscanexternal-media-without-importauthenticatedintrusiveexternal_media_without_import_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:external_media_without_import_project:external_media_without_import:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2