The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/69f33e20-8ff4-491c-8f37-a4eadd4ea8cf/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/69f33e20-8ff4-491c-8f37-a4eadd4ea8cf/ | Exploit Third Party Advisory |
Configurations
History
16 May 2025, 12:44
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-918 | |
First Time |
Godaddy
Godaddy coblocks |
|
CPE | cpe:2.3:a:godaddy:coblocks:*:*:*:*:*:wordpress:*:* | |
References | () https://wpscan.com/vulnerability/69f33e20-8ff4-491c-8f37-a4eadd4ea8cf/ - Exploit, Third Party Advisory |
21 Nov 2024, 09:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/69f33e20-8ff4-491c-8f37-a4eadd4ea8cf/ - |
01 Aug 2024, 13:59
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
24 Jul 2024, 12:55
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
23 Jul 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-23 06:15
Updated : 2025-05-16 12:44
NVD link : CVE-2024-4260
Mitre link : CVE-2024-4260
CVE.ORG link : CVE-2024-4260
JSON object : View
Products Affected
godaddy
- coblocks
CWE
CWE-918
Server-Side Request Forgery (SSRF)