Description
WordPress Plugin Flog is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin Flog version 1.0beta3 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly validated or disable the plugin until a fix is available
References
Related Vulnerabilities
MySQL CVE-2015-4858 Vulnerability (CVE-2015-4858)
Oracle Database Server CVE-2010-2390 Vulnerability (CVE-2010-2390)
WordPress Plugin WordPress Payments-GetPaid Cross-Site Scripting (2.3.3)
WordPress 4.0.x Prototype Pollution (4.0 - 4.0.34)
LimeSurvey Incorrect Default Permissions Vulnerability (CVE-2019-16183)