wp-includes/http.php in WordPress prior to 3.7.5, 3.8.x prior to 3.8.5, 3.9.x prior to 3.9.3, and 4.x prior to 4.0.1 allows remote malicious users to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wordpress wordpress |
||
wordpress wordpress 3.8 |
||
wordpress wordpress 3.8.1 |
||
wordpress wordpress 3.9.1 |
||
wordpress wordpress 3.9.2 |
||
wordpress wordpress 4.0 |
||
wordpress wordpress 3.8.2 |
||
wordpress wordpress 3.8.4 |
||
wordpress wordpress 3.8.3 |
||
wordpress wordpress 3.9 |