Description
WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.
Remediation
References
Related Vulnerabilities
WordPress Plugin Admin Font Editor Cross-Site Scripting (1.8)
WordPress Plugin Manual Image Crop Cross-Site Scripting (1.10)
Joomla CVE-2018-15881 Vulnerability (CVE-2018-15881)
WordPress 3.8.x Multiple Vulnerabilities (3.8 - 3.8.17)
Joomla Use of Insufficiently Random Values Vulnerability (CVE-2012-1562)