What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Faizaan Gagan Course Migration for LearnDash allows Server Side Request Forgery.This issue affects Course Migration for LearnDash: from 1.0.2 through n/a.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in Faizaan Gagan Course Migration for LearnDash allows Server Side Request Forgery.This issue affects Course Migration for LearnDash: from 1.0.2 through n/a.
Explanation of Vulnerability in Simple Terms
Course Migration for LearnDash contains a server-side request forgery (SSRF) vulnerability that allows authenticated users to make the site send requests to internal or external systems on their behalf. An attacker with low-level site access can probe internal networks, access metadata services, or interact with backend systems. The vulnerability affects version 1.0.2 and requires an active site account to exploit.
What an attacker can do
Make the site send HTTP requests to internal systems or external URLs, potentially accessing sensitive data or triggering unintended actions.
Potential impact on your site
A compromised or malicious user account can probe your internal network, access cloud metadata, or interact with backend services connected to your site.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities