HIGH🇵🇱 Wersja polska

CVE-2022-1037

CVSS 7.2v3.1pub. 2022-04-18upd. 2024-11-21

The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Villatheme Exmage

    APP
    Villatheme
    < 1.0.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2024-8277CRITICAL9.8PL ✓same vendor

Authentication bypass w WooCommerce Photo Reviews Premium dla WordPress

CVE-2022-41623HIGH7.5same vendor

Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium pl...

CVE-2024-12861MEDIUM6.5same vendor

The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all vers...

CVE-2024-49288MEDIUM5.9same vendor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaThe...

CVE-2024-1687MEDIUM5.4same vendor

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unau...