S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-1398 Scanner

CVE-2022-1398 scanner - Authenticated Blind Server-Side Request Forgery vulnerability in External Media without Import

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1398
6.5
CVSS

The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are external medias, which could allow any authenticated users, such as subscriber to perform blind SSRF attacks

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
External Media without Import
1.1.2
Updated Aug 22, 2026View on NVD →
Detail

The External Media without Import plugin for WordPress allows users to add media to their website from external URLs without having to import the media into the WordPress media library. It is intended for website administrators and content creators who wish to streamline their content management process by linking directly to external media. This functionality is particularly useful for websites that frequently update their content with images, videos, and other media from external sources. The plugin simplifies the process of using external media, making it more efficient and less resource-intensive for websites. It is a popular tool among WordPress users for its convenience and utility in content management.

The SSRF vulnerability is triggered when a user submits a request to add external media through the plugin's functionality. The plugin fails to adequately verify if the submitted URLs are genuinely external media and does not check the user's authorization to perform the action. This oversight allows attackers to craft malicious URLs that can cause the server to interact with unintended internal or external services. The flaw is particularly concerning because it can be exploited by any authenticated user, making it a significant risk for websites with open registration.

Exploitation of this vulnerability could lead to several adverse effects, including the unauthorized disclosure of sensitive information from internal network resources accessible to the server. Attackers could also leverage this flaw to perform port scanning of internal networks, facilitating further attacks. In some cases, if the server can interact with other services that interpret the incoming requests as commands, it could lead to more severe attacks, such as data manipulation or remote code execution, depending on the nature of the accessed service.

Joining S4E offers unparalleled benefits in safeguarding your WordPress site against vulnerabilities like CVE-2022-1398 in the External Media without Import plugin. Our platform provides comprehensive vulnerability scanning and threat management services, enabling you to detect and address security issues before they can be exploited. With our proactive monitoring and detailed reports, you can ensure your site's security is always up to date, protecting your digital assets and maintaining the trust of your users. Enhance your website's security posture and stay ahead of threats with S4E.

 

References

Solution Advice
  1. Upgrade the External Media without Import plugin to version 1.1.3 or higher as soon as possible to mitigate the SSRF vulnerability.
  2. Regularly update all WordPress plugins and themes to their latest versions to protect against known vulnerabilities.
  3. Implement access controls and user role management to restrict the capabilities of authenticated users based on their necessity.
  4. Consider using security plugins that offer additional protections, such as firewall capabilities and intrusion detection, to further secure your WordPress site.
  5. Educate users with access to your WordPress site about the importance of security and encourage the practice of strong password policies and cautious link handling.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.