WordPress security changelog
CRITICAL CVE-2019-16932 Modified

Visualizer: Server-side request forgery

Visualizer is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.

CVE / CNA score 10.0 CVSS · cve@mitre.org
NVD score 10.0 CVSS 3.1 · nvd@nist.gov
Component
Visualizer
Plugin slug
visualizer
Affected
See vendor advisory
Safe version
See mitigation notes
Published
Sep 30, 2019
Weakness
CWE-918 — Server-Side Request Forgery (SSRF)

This CVE was published Sep 30, 2019 and is one of 13 known issues for this plugin.

Patch or disable the affected component.

Update Visualizer to a release outside the affected range, or disable and remove it until a fixed version is available.

Technical description

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

NVD vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Primary and upstream sources