CVE-2022-3708
Last modified
CVE-2022-3708 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This makes it possible for authenticated users to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This makes it possible for authenticated users to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Web Stories | < 1.25.0 |
References
- https://github.com/GoogleForCreators/web-stories-wp/commit/3ad2099f95155d658624ffac2e34ce0da739e34bPatch, Third Party Advisory
- https://github.com/GoogleForCreators/web-stories-wp/compare/v1.24.0...v1.25.0Patch, Release Notes, Third Party Advisory
- https://wordpress.org/plugins/web-storiesProduct, Release Notes, Third Party Advisory
- https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-3708Third Party Advisory
- https://github.com/GoogleForCreators/web-stories-wp/commit/3ad2099f95155d658624ffac2e34ce0da739e34bPatch, Third Party Advisory
- https://github.com/GoogleForCreators/web-stories-wp/compare/v1.24.0...v1.25.0Patch, Release Notes, Third Party Advisory
- https://wordpress.org/plugins/web-storiesProduct, Release Notes, Third Party Advisory
- https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-3708Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3708?
How severe is CVE-2022-3708?
How do I fix CVE-2022-3708?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-37074H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a …7.8
- CVE-2022-37075TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to con…7.8
- CVE-2022-37076TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to con…7.8
- CVE-2022-37077TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to con…7.8
- CVE-2022-37078TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to con…7.8
- CVE-2022-37079TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to con…7.8
- CVE-2022-37080TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to con…7.8
- CVE-2022-37081TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to con…7.8
- CVE-2022-37082TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to con…7.8
- CVE-2022-37083TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to con…7.8
- CVE-2022-37084TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to con…7.8
- CVE-2022-37085H3C H200 H200V100R004 was discovered to contain a stack over…9.8
Are you affected by CVE-2022-3708?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
