
We found results for “”
CVE-2023-23684
Good to know:

Date: November 12, 2023
Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.
Language: PHP
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Server-Side Request Forgery (SSRF)
CWE-918Top Fix

Upgrade Version
Upgrade to version wp-graphql/wp-graphql - dev-jasonbahl-patch-5;wp-graphql/wp-graphql - 1.4.2;wp-graphql/wp-graphql - dev-feat/#2983-test-against-wp-6.4;wp-graphql/wp-graphql - dev-justlevine-patch-1;wp-graphql/wp-graphql - 1.3.4;wp-graphql/wp-graphql - dev-release/v1.8.7;wp-graphql/wp-graphql - 1.4.0;wp-graphql/wp-graphql - dev-release/v1.5.6;wp-graphql/wp-graphql - dev-release/v1.5.8;wp-graphql/wp-graphql - dev-release/v1.6.3;wp-graphql/wp-graphql - dev-release/v1.14.6;wp-graphql/wp-graphql - dev-dependabot/npm_and_yarn/graphql-16.8.1;wp-graphql/wp-graphql - dev-release/v1.0.2;wp-graphql/wp-graphql - dev-bug/#961/negative-performance-for-user-model;wp-graphql/wp-graphql - dev-feature/phpcs-refactor;wp-graphql/wp-graphql - dev-release/v1.6.12;wp-graphql/wp-graphql - dev-dependabot/npm_and_yarn/src/Admin/GraphiQL/app/urijs-1.19.7;wp-graphql/wp-graphql - dev-release/v1.14.8;wp-graphql/wp-graphql - dev-dependabot/npm_and_yarn/terser-5.14.2;wp-graphql/wp-graphql - 1.4.1;wp-graphql/wp-graphql - dev-chore/change-slack-to-discord;wp-graphql/wp-graphql - dev-fix/#2809-max-age-error;wp-graphql/wp-graphql - dev-dependabot/npm_and_yarn/npm_and_yarn-04107d1454;wp-graphql/wp-graphql - v1.1.8.0;wp-graphql/wp-graphql - dev-release/v2.0.0;wp-graphql/wp-graphql - 3.0.1;wp-graphql/wp-graphql - dev-dependabot/npm_and_yarn/src/Admin/GraphiQL/app/url-parse-1.5.10;wp-graphql/wp-graphql - dev-dependabot/npm_and_yarn/babel/traverse-7.23.2;wp-graphql/wp-graphql - dev-rebrand;wp-graphql/wp-graphql - dev-fix/interface-recursion;wp-graphql/wp-graphql - dev-ci/update-workflow-actions;wp-graphql/wp-graphql - dev-feature/github-code-analysis-workflow;wp-graphql/wp-graphql - dev-release/v1.6.1;wp-graphql/wp-graphql - dev-release/v1.10.0;wp-graphql/wp-graphql - dev-feature/#1947-let-objects-register-connections;wp-graphql/wp-graphql - dev-feature/#993-stop-versioning-deps;wp-graphql/wp-graphql - dev-dependabot/composer/rmccue/requests-1.8.0;wp-graphql/wp-graphql - dev-dependabot/composer/composer-65e32c6de6;wp-graphql/wp-graphql - dev-dependabot/npm_and_yarn/axios-and-wordpress/scripts-1.6.5;wp-graphql/wp-graphql - 1.4.4;wp-graphql/wp-graphql - dev-release/v1.5.5;wp-graphql/wp-graphql - dev-dependabot/npm_and_yarn/word-wrap-1.2.4;wp-graphql/wp-graphql - 3.0.0;wp-graphql/wp-graphql - dev-fix/#1831-admin-notice-if-composer-deps-not-installed;wp-graphql/wp-graphql - dev-revert-2890-fix/cache-key-url;wp-graphql/wp-graphql - dev-chore/update-docs;wp-graphql/wp-graphql - dev-release/v1.5.1;wp-graphql/wp-graphql - dev-dependabot/composer/composer/composer-1.10.22;wp-graphql/wp-graphql - 1.3.3;wp-graphql/wp-graphql - dev-release/v1.9.1;wp-graphql/wp-graphql - 1.4.3;wp-graphql/wp-graphql - dev-release/v1.7.2;wp-graphql/wp-graphql - dev-feat/schema-customization/graceful-fail-for-invalid-registration;wp-graphql/wp-graphql - dev-dependabot/npm_and_yarn/npm_and_yarn-5134b82be1;wp-graphql/wp-graphql - 1.3.2;wp-graphql/wp-graphql - dev-release/v1.5.4;wp-graphql/wp-graphql - dev-dependabot/npm_and_yarn/src/Admin/GraphiQL/app/url-parse-1.5.7;wp-graphql/wp-graphql - dev-devops/wp-graphql-testcase-update;wp-graphql/wp-graphql - dev-release/v1.6.8;wp-graphql/wp-graphql - dev-dependabot/npm_and_yarn/npm_and_yarn-9218438be0;wp-graphql/wp-graphql - dev-release/v1.8.4;wp-graphql/wp-graphql - dev-dependabot/composer/guzzlehttp/guzzle-6.5.6;wp-graphql/wp-graphql - dev-playground-changes-2024-11-05T18-05-29-062Z;wp-graphql/wp-graphql - dev-release/v1.7.0
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | HIGH |
User Interaction (UI): | NONE |
Scope (S): | CHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |