Vulnerability Details CVE-2022-2912
The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logged in admin change the url value performing unwanted crawls on third-party sites (SSRF).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.6%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2022-2912
-
cpe:2.3:a:craw-data_project:craw-data:*