VYPR

Onestore Sites

by Sainwp

CVEs (1)

  • CVE-2024-13905MedFeb 27, 2025
    risk 0.34cvss 5.3epss 0.00

    The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.1.1 via the class-export.php file. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the…