S4E just found a medium-severity finding from http usage detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2022-45835 Scanner

CVE-2022-45835 scanner - Server-Side Request Forgery vulnerability in WordPress PhonePe Payment Solutions

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-45835
7.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
PhonePe Payment Solutionsby PhonePe
n/a
phonepe_payment_solutionsby phonepe
0
Updated Aug 22, 2026View on NVD →
Detail

The WordPress PhonePe Payment Solutions plugin facilitates seamless integration of PhonePe payment gateway services into WordPress sites. It allows site owners to offer a convenient payment option to their users, supporting a wide range of payment methods. This plugin is especially useful for e-commerce platforms, subscription-based services, and any online business looking to provide their customers with secure and efficient payment processing through PhonePe. It's designed for ease of use, ensuring a smooth transaction process for both site owners and their customers.

CVE-2022-45835 reveals a high-severity Server-Side Request Forgery (SSRF) vulnerability in the WordPress PhonePe Payment Solutions plugin versions up to and including 1.0.15. This flaw permits attackers to induce the server to make HTTP requests to an arbitrary domain, potentially leading to unauthorized access to sensitive information, modification of data, or execution of unwanted actions on behalf of the server within the internal network or the internet.

The vulnerability stems from inadequate validation and sanitization of user-supplied inputs in the plugin's functionalities. Specifically, it allows unauthenticated users to manipulate the URL parameter in requests to the server, facilitating SSRF attacks. This can be exploited by sending a specially crafted request to the plugin's endpoint, causing the server to interact with an attacker-controlled domain or IP address. The exploit can lead to sensitive data exposure, internal system reconnaissance, or interaction with other internal network services.

Exploiting this SSRF vulnerability could have severe implications, including exposure of internal network configurations, access to internal services, data breaches, and potentially, lateral movement within the network. Attackers could leverage this vulnerability to probe internal systems, extract sensitive information, or execute unauthorized commands, posing a significant risk to the security and privacy of the affected WordPress site and its users.

By subscribing to the S4E platform, users gain access to an extensive suite of security tools designed to identify and address vulnerabilities such as CVE-2022-45835 in WordPress plugins like PhonePe Payment Solutions. Our platform offers detailed vulnerability assessments, actionable remediation guidance, and continuous monitoring capabilities to enhance your website's security posture. Joining S4E empowers you to proactively defend against the latest cyber threats, ensuring your site remains secure and trustworthy.

 

References

Solution Advice
  1. Immediately update the WordPress PhonePe Payment Solutions plugin to version 2.0.0 or higher, which contains a fix for the SSRF vulnerability.
  2. Regularly update all WordPress plugins, themes, and the core installation to their latest versions.
  3. Employ network-level security measures to restrict outbound requests from the server, mitigating potential SSRF attack vectors.
  4. Utilize security plugins and firewalls that offer additional protections against SSRF and other types of vulnerabilities.
  5. Consider conducting periodic security audits and penetration testing to identify and remediate vulnerabilities in your WordPress site.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.