CVE-2020-24063
WordPress vulnerability analysis and mitigation

Overview

The Canto plugin version 1.3.0 for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability through the subdomain parameter in includes/lib/download.php. This vulnerability was discovered in 2020 and assigned CVE-2020-24063. The issue affects the plugin up to version 3.0.8, allowing unauthenticated users to make requests to internal or external servers (WPScan).

Technical details

The vulnerability exists in multiple files within the plugin, specifically in /includes/lib/tree.php, /includes/lib/detail.php, /includes/lib/get.php, and /includes/lib/download.php. The SSRF vulnerability can be exploited through the 'subdomain' parameter, where all requests to arbitrary domains/IPs are made using the HTTPS protocol. The vulnerability has been assigned a CVSS 3.1 Base Score of 7.2 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N (NVD).

Impact

The vulnerability allows attackers to perform various attacks including Cross-Site Scripting, Cross-Site Port Attack, abuse Cross-Origin resource sharing, or access internal resources hosted on the server. This can lead to unauthorized access to internal systems and potential data exposure (GitHub Advisory).

Exploitability

The vulnerability can be exploited by unauthenticated users by navigating to the affected endpoints and adding malicious payloads to the 'subdomain' parameter. A specific exploitation technique requires using the '?' character in the payload as a mandatory bypass to conduct the attack (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in version 3.0.9 of the Canto plugin. Users are advised to update to the latest version to mitigate this security issue (WordPress Plugin).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-65640HIGH8.8
  • wordpress
NoYesAug 17, 2026
CVE-2026-11801HIGH7.5
  • wpadverts
NoYesAug 18, 2026
CVE-2026-13700MEDIUM5.9
  • wooms
NoNoAug 17, 2026
CVE-2026-14832MEDIUM5.3
  • shopsmart-loyalty-for-woocommerce
NoNoAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management