Description
The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file due to a user-supplied URL request value that gets called by a curl requests. This affects versions up to, and including, 1.8.0.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Uninstall plugin.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-25700 | The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file due to a user-supplied URL request value that gets called by a curl requests. This affects versions up to, and including, 1.8.0. |
References
History
Mon, 31 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-03-31T18:20:31.937Z
Reserved: 2021-08-20T00:00:00.000Z
Link: CVE-2021-39339
Updated: 2024-08-04T02:06:42.215Z
Status : Modified
Published: 2021-09-22T11:15:07.503
Modified: 2024-11-21T06:19:16.553
Link: CVE-2021-39339
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD