
Cloud Vulnerability DB
A community-led vulnerabilities database
The Canto plugin version 1.3.0 for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability through the subdomain parameter in includes/lib/download.php. This vulnerability was discovered in 2020 and assigned CVE-2020-24063. The issue affects the plugin up to version 3.0.8, allowing unauthenticated users to make requests to internal or external servers (WPScan).
The vulnerability exists in multiple files within the plugin, specifically in /includes/lib/tree.php, /includes/lib/detail.php, /includes/lib/get.php, and /includes/lib/download.php. The SSRF vulnerability can be exploited through the 'subdomain' parameter, where all requests to arbitrary domains/IPs are made using the HTTPS protocol. The vulnerability has been assigned a CVSS 3.1 Base Score of 7.2 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N (NVD).
The vulnerability allows attackers to perform various attacks including Cross-Site Scripting, Cross-Site Port Attack, abuse Cross-Origin resource sharing, or access internal resources hosted on the server. This can lead to unauthorized access to internal systems and potential data exposure (GitHub Advisory).
The vulnerability can be exploited by unauthenticated users by navigating to the affected endpoints and adding malicious payloads to the 'subdomain' parameter. A specific exploitation technique requires using the '?' character in the payload as a mandatory bypass to conduct the attack (GitHub Advisory).
The vulnerability has been fixed in version 3.0.9 of the Canto plugin. Users are advised to update to the latest version to mitigate this security issue (WordPress Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."