Description
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
Remediation
References
Related Vulnerabilities
WordPress Plugin HAL Cross-Site Scripting (2.1.1)
Roundcube Improper Access Control Vulnerability (CVE-2016-9920)
WordPress Plugin AnyComment Cross-Site Scripting (0.0.32)
WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker SQL Injection (7.3.4)
WordPress Plugin Side Menu Lite-add sticky fixed buttons SQL Injection (2.2.1)