WordPress Plugin Vulnerabilities

affiliate-toolkit < 3.4.3 - Unauthenticated SSRF

Description

The plugin lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.

Version 3.3.6 introduces some measures to limit access to localhost, and a separate file for storing an arbitrary site key. However, other RFC1918 addresses are not filtered, and the site key file is under a hardcoded pathname, and may be accessible by unauthenticated visitors, effectively reducing the security of the endpoint.

Proof of Concept

Affects Plugins

References

Classification

Type
SSRF
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Ji Yuchen
Submitter
Ji Yuchen
Verified
Yes

Timeline

Publicly Published
2023-12-11 (about 2 years ago)
Added
2023-12-11 (about 2 years ago)
Last Updated
2023-12-11 (about 2 years ago)

Other