WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.
Score: 0.0
Priority: Unclassified
Score: 0.00529Percentile: 0.66219
CVSS v3.1 Score: 8.6
Severity: HIGH
← Back to Home