Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-42653 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks |
Fri, 09 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-05-09T18:57:04.900Z
Reserved: 2022-09-20T00:00:00.000Z
Link: CVE-2022-3247
Updated: 2024-08-03T01:07:05.647Z
Status : Modified
Published: 2022-10-25T17:15:56.873
Modified: 2025-05-09T19:15:54.770
Link: CVE-2022-3247
No data.
OpenCVE Enrichment
No data.
EUVD