QID 731166
Date Published: 2024-02-26
QID 731166: WordPress Affiliate-toolkit Plugin Server Side Request Forgery (SSRF) Vulnerability
The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.
Affected Version
affiliate-toolkit less than 3.4.3
QID Detection Logic (Un-Authenticated):
QID sends GET request to plugins/affiliate-toolkit-starter/tools/atkp_imagereceiver.php path, to check vulnerability.
On successful exploitation allowing unauthenticated visitors to make requests to arbitrary URL's
Solution
Vendor fixed issue in 3.4.3. Refer to advisory here for updates and patch information.
Vendor References
- affiliate-toolkit -
wpscan.com/vulnerability/39ed4934-3d91-4924-8acc-25759fef9e81/
CVEs related to QID 731166
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-5877 |
|