Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A server-side request forgery vulnerability in the CF7 to Webhook WordPress plugin (versions up to and including 5.0.0) allows unauthenticated attackers to direct the vulnerable web server to make arbitrary requests against internal network resources. Exploitation requires a specific administrator-configured webhook condition, reducing but not eliminating real-world risk. Organizations running this plugin on internet-facing WordPress sites should assess their webhook configurations and apply remediation immediately.

Author

Tech Jacks Solutions