Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2022-0591

Severity
9.1CRITICAL
EPSS
87.9%
top 0.52%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 21
Latest updateMar 22

Description

The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

CVEListV5unknown/formcraft3.8.283.8.28

🔴Vulnerability Details

3
GHSA
GHSA-x9wp-hprc-2gvq: The FormCraft WordPress plugin before 32022-03-22
CVEList
Formcraft3 < 3.8.28 - Unauthenticated SSRF2022-03-21
VulnCheck
subtlewebinc formcraft3 Server-Side Request Forgery (SSRF)2022

💥Exploits & PoCs

1
Nuclei
Formcraft3 <3.8.28 - Server-Side Request Forgery
CVE-2022-0591 (CRITICAL CVSS 9.1) | The FormCraft WordPress plugin befo | cvebase.io