CVE Vulnerabilities

CVE-2013-0235

Published: Jul 08, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress*3.5.0 (including)
WordpressWordpress0.71 (including)0.71 (including)
WordpressWordpress1.0 (including)1.0 (including)
WordpressWordpress1.0.1 (including)1.0.1 (including)
WordpressWordpress1.0.2 (including)1.0.2 (including)
WordpressWordpress1.1.1 (including)1.1.1 (including)
WordpressWordpress1.2 (including)1.2 (including)
WordpressWordpress1.2.1 (including)1.2.1 (including)
WordpressWordpress1.2.2 (including)1.2.2 (including)
WordpressWordpress1.2.3 (including)1.2.3 (including)
WordpressWordpress1.2.4 (including)1.2.4 (including)
WordpressWordpress1.2.5 (including)1.2.5 (including)
WordpressWordpress1.2.5-a (including)1.2.5-a (including)
WordpressWordpress1.3 (including)1.3 (including)
WordpressWordpress1.3.2 (including)1.3.2 (including)
WordpressWordpress1.3.3 (including)1.3.3 (including)
WordpressWordpress1.5 (including)1.5 (including)
WordpressWordpress1.5.1 (including)1.5.1 (including)
WordpressWordpress1.5.1.1 (including)1.5.1.1 (including)
WordpressWordpress1.5.1.2 (including)1.5.1.2 (including)
WordpressWordpress1.5.1.3 (including)1.5.1.3 (including)
WordpressWordpress1.5.2 (including)1.5.2 (including)
WordpressWordpress1.6.2 (including)1.6.2 (including)
WordpressWordpress2.0 (including)2.0 (including)
WordpressWordpress2.0.1 (including)2.0.1 (including)
WordpressWordpress2.0.2 (including)2.0.2 (including)
WordpressWordpress2.0.4 (including)2.0.4 (including)
WordpressWordpress2.0.5 (including)2.0.5 (including)
WordpressWordpress2.0.6 (including)2.0.6 (including)
WordpressWordpress2.0.7 (including)2.0.7 (including)
WordpressWordpress2.0.8 (including)2.0.8 (including)
WordpressWordpress2.0.9 (including)2.0.9 (including)
WordpressWordpress2.0.10 (including)2.0.10 (including)
WordpressWordpress2.0.11 (including)2.0.11 (including)
WordpressWordpress2.1 (including)2.1 (including)
WordpressWordpress2.1.1 (including)2.1.1 (including)
WordpressWordpress2.1.2 (including)2.1.2 (including)
WordpressWordpress2.1.3 (including)2.1.3 (including)
WordpressWordpress2.2 (including)2.2 (including)
WordpressWordpress2.2.1 (including)2.2.1 (including)
WordpressWordpress2.2.2 (including)2.2.2 (including)
WordpressWordpress2.2.3 (including)2.2.3 (including)
WordpressWordpress2.3 (including)2.3 (including)
WordpressWordpress2.3.1 (including)2.3.1 (including)
WordpressWordpress2.3.2 (including)2.3.2 (including)
WordpressWordpress2.3.3 (including)2.3.3 (including)
WordpressWordpress2.5 (including)2.5 (including)
WordpressWordpress2.5.1 (including)2.5.1 (including)
WordpressWordpress2.6 (including)2.6 (including)
WordpressWordpress2.6.1 (including)2.6.1 (including)
WordpressWordpress2.6.2 (including)2.6.2 (including)
WordpressWordpress2.6.3 (including)2.6.3 (including)
WordpressWordpress2.6.5 (including)2.6.5 (including)
WordpressWordpress2.7 (including)2.7 (including)
WordpressWordpress2.7.1 (including)2.7.1 (including)
WordpressWordpress2.8 (including)2.8 (including)
WordpressWordpress2.8.1 (including)2.8.1 (including)
WordpressWordpress2.8.2 (including)2.8.2 (including)
WordpressWordpress2.8.3 (including)2.8.3 (including)
WordpressWordpress2.8.4 (including)2.8.4 (including)
WordpressWordpress2.8.4-a (including)2.8.4-a (including)
WordpressWordpress2.8.5 (including)2.8.5 (including)
WordpressWordpress2.8.5.1 (including)2.8.5.1 (including)
WordpressWordpress2.8.5.2 (including)2.8.5.2 (including)
WordpressWordpress2.8.6 (including)2.8.6 (including)
WordpressWordpress2.9 (including)2.9 (including)
WordpressWordpress2.9.1 (including)2.9.1 (including)
WordpressWordpress2.9.1.1 (including)2.9.1.1 (including)
WordpressWordpress2.9.2 (including)2.9.2 (including)
WordpressWordpress3.3 (including)3.3 (including)
WordpressWordpress3.3.1 (including)3.3.1 (including)
WordpressWordpress3.3.2 (including)3.3.2 (including)
WordpressWordpress3.3.3 (including)3.3.3 (including)
WordpressWordpress3.4.0 (including)3.4.0 (including)
WordpressWordpress3.4.1 (including)3.4.1 (including)
WordpressWordpress3.4.2 (including)3.4.2 (including)
WordpressUbuntuhardy*
WordpressUbuntulucid*
WordpressUbuntuoneiric*
WordpressUbuntuprecise*
WordpressUbuntuquantal*
WordpressUbuntuupstream*

References