QID 150362
Date Published: 2021-09-02
QID 150362: WordPress XML-RPC Pingback Vulnerability
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database.
XML-RPC in WordPress is an API which allows developers who make third party application and services the ability to interact to your WordPress site using features like Trackbacks and Pingbacks.
The Pingback feature of XML-RPC API allows attacks like DDOS and Server-Side Request Forgery (SSRF) either against the server hosting WordPress or against a target server.
QID Detection Logic:
This detection sends a POST request with XML data with invalid URL to verify the presence of vulnerability.
On Successful exploitation, an attacker can control a WordPress site to conduct DDOS or Server-Side Request Forgery (SSRF) attack against a target server.
CVEs related to QID 150362
| Advisory ID | Software | Component | Link |
|---|