VYPR
Unrated severityNVD Advisory· Published Mar 25, 2025· Updated Mar 25, 2025

Downloable by American Osteopathic Association <= 0.1.0 - Unauthenticated SSRF

CVE-2024-13618

Description

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.