CVE-2023-7253

The Import WP WordPress plugin before 2.13.1 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:importwp:import_wp:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-04-24 05:15

Updated : 2025-05-08 19:10


NVD link : CVE-2023-7253

Mitre link : CVE-2023-7253

CVE.ORG link : CVE-2023-7253


JSON object : View

Products Affected

importwp

  • import_wp
CWE
CWE-918

Server-Side Request Forgery (SSRF)