• Hi every ine my website containing this

    WordPress <= 6.1.1 – Unauth. Blind SSRF vulnerability

    Can you advise if and when there will be a fix for this please?

    The page I need help with: [log in to see the link]

Viewing 6 replies - 1 through 6 (of 6 total)
  • Moderator Steven Stern (sterndata)

    (@sterndata)

    Volunteer Forum Moderator

    A CVE (tracking number) was recently issues for a long standing DNS re-binding exploit (and with a CVE, the security plugins now toot it).
    It has a very low priority, since it relies on someone hijacking your server’s DNS resolver, you can find some details, and responses, at?https://portswigger.net/daily-swig/six-year-old-blind-ssrf-vulnerability-in-wordpress-core-feature-could-enable-ddos-attacks

    Thread Starter mashoodkhan321

    (@mashoodkhan321)

    How can i fixed this

    desingshine

    (@desingshine)

    Buenos días, tengo exactamente el mismo problema.
    Y se me están instalando carpetas extra?as en la raíz del directorio de la web.

    #WordPress <= 6.1.1 – Unauth. Blind SSRF vulnerability
    -Vulnerability type: Server Side Request Forgery (SSRF)
    -No Update Available

    ?Qué puedo hacer para solucionarlo?
    Gracias.

    Moderator Steven Stern (sterndata)

    (@sterndata)

    Volunteer Forum Moderator

    @desingshine Please read my reply, above.

    4briang

    (@4briang)

    According to the post from @sterndata , it uses the pingback functionality?of WordPress. So probably a good idea to uncheck pingbacks under /wp-admin/options-discussion.php. It seems like the security plugins should see that you’ve done this instead of just listing the vulnerability. I believe WPEngine is disabling the XMLRPC API although it might be on on older installed sites. Also the original post has a filter to add to functions.php of your child theme that can turn-off the pingback functionality globally. I believe this has been best practice since the vulnerability first came out.

    desingshine

    (@desingshine)

    Lo voy a probar, muchísimas gracias 4briang!

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘WordPress <= 6.1.1 – Unauth. Blind SSRF vulnerability’ is closed to new replies.