CVE-2013-0235

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/07/2013
Last modified:
11/04/2025

Description

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 3.5.0 (including)
cpe:2.3:a:wordpress:wordpress:0.71:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.5:a:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.3.2:*:*:*:*:*:*:*