Vulnerability Details CVE-2024-1758
The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.40.3 via the wc_sf_url_check function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. CVE-2024-32803 appears to be a duplicate of this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.5%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2024-1758
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.30.3
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.30.4
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.30.5
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.31.0
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.31.1
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.31.2
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.31.3
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.31.4
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.32.0
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.40.0
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.40.1
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.40.2
-
cpe:2.3:a:superfaktura:superfaktura_woocommerce:1.40.3