CVE-2023-7253

The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:importwp:import_wp:*:*:*:*:*:wordpress:*:*

History

08 May 2025, 19:10

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/aeefcc01-bbbf-4d86-9cfd-ea0f9a85e1a5/ - () https://wpscan.com/vulnerability/aeefcc01-bbbf-4d86-9cfd-ea0f9a85e1a5/ - Exploit, Third Party Advisory
First Time Importwp
Importwp import Wp
CPE cpe:2.3:a:importwp:import_wp:*:*:*:*:*:wordpress:*:*
CWE CWE-918

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/aeefcc01-bbbf-4d86-9cfd-ea0f9a85e1a5/ - () https://wpscan.com/vulnerability/aeefcc01-bbbf-4d86-9cfd-ea0f9a85e1a5/ -

03 Jul 2024, 01:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

24 Apr 2024, 13:39

Type Values Removed Values Added
Summary
  • (es) El complemento Import WP WordPress anterior a 2.13.1 no impide que los usuarios con función de administrador hagan ping al realizar ataques SSRF, lo que puede ser un problema en configuraciones multisitio.

24 Apr 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-24 05:15

Updated : 2025-05-08 19:10


NVD link : CVE-2023-7253

Mitre link : CVE-2023-7253

CVE.ORG link : CVE-2023-7253


JSON object : View

Products Affected

importwp

  • import_wp
CWE
CWE-918

Server-Side Request Forgery (SSRF)