Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-8013

Опубликовано: 15 авг. 2025
Источник: nvd
CVSS3: 3.8
EPSS Низкий

Описание

The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

EPSS

Процентиль: 7%
0.00032
Низкий

3.8 Low

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 3.8
github
30 дней назад

The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

EPSS

Процентиль: 7%
0.00032
Низкий

3.8 Low

CVSS3

Дефекты

CWE-918