WordPress Plugin Vulnerabilities

Fusion Builder < 3.6.2 - Unauthenticated SSRF

Description

The plugin, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

Proof of Concept

Affects Plugins

Fixed in 3.6.2

Affects Themes

Fixed in 7.6.2

References

Classification

Type
SSRF
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Calum Elrick
Submitter
calum.elrick@rootshellsecurity.net
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2022-04-19 (about 3 years ago)
Added
2022-04-19 (about 3 years ago)
Last Updated
2022-04-20 (about 3 years ago)

Other