Inadequate IP Address Validation in WordPress Allows SSRF Bypass

Inadequate IP Address Validation in WordPress Allows SSRF Bypass

CVE-2016-4029 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

Learn more about our Web Application Penetration Testing UK.