CVE-2024-10814

Published Nov 9, 2024

Last updated 5 days ago

Overview

Description
The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5 via the ce_get_file() function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Source
security@wordfence.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
6.4
Impact score
2.7
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

security@wordfence.com
CWE-918

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2024-10814 (Published: 2024-11-09) affects specific versions of WordPress plugins. Ensure your site is secure by updating to the latest version available. Check the changeset for detailed remediation steps: https://t.co/1MawjJUV2R #WordPress #CyberSecurity #CVE

    @transilienceai

    13 Nov 2024

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2024-10814 (Published: 2024-11-09) affects specific versions of WordPress plugins. Ensure your site is secure by updating to the latest version as detailed in the changelog: https://t.co/1MawjJUV2R. Don't leave your site vulnerable—act now! #WordPress #CVE

    @transilienceai

    13 Nov 2024

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2024-10814 (Published: 2024-11-09) - A high-severity vulnerability affecting https://t.co/46Yxyk3zIZ. Ensure your WordPress installation is updated to the latest version to mitigate risks. Check the changeset for details: https://t.co/1MawjJUV2R #WordPress #CVE… https://t.

    @transilienceai

    13 Nov 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2024-10814 (Published: 2024-11-09) - A high-severity vulnerability affects https://t.co/46Yxyk47yx. Exploited in various versions, it poses significant risks. 🛡️ Ensure your site is secure by updating to the latest version. For details, check the changeset:… https://t.co/

    @transilienceai

    9 Nov 2024

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CVE-2024-10814 (Published: 2024-11-09) - A high-severity vulnerability affects https://t.co/46Yxyk47yx. Ensure your installations are updated to the latest version to mitigate risks. Check the changeset for details: https://t.co/1MawjJVsSp Stay secure! #WordPress #CVE

    @transilienceai

    9 Nov 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-10814 Server-Side Request Forgery in WordPress Code Embed Plugin The Code Embed plugin for WordPress has a Server-Side Request Forgery vulnerability. All versions up to 2.5 are affected through the ce_ge... https://t.co/4CqWdxLVpk

    @VulmonFeeds

    9 Nov 2024

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2024-10814 The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5 via the ce_get_file() function. This makes … https://t.co/VjL8wQruD7

    @CVEnew

    9 Nov 2024

    346 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes