{"error":0,"message":null,"data":{"name":"Cloudflare","plugin":"cloudflare","link":"https:\/\/wordpress.org\/plugins\/cloudflare\/","latest":"1783969860","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"3821bc04f7a680372040b842e3b9946a9b13efa82dd55b7ea62fbad7b345f7b8","name":"Cloudflare [cloudflare] < 1.3.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f08cd4b8d2fd9232b03273f997f5656375cae41d","name":"WordPress CloudFlare Plugin <= 1.3.20 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cloudflare\/vulnerability\/wordpress-cloudflare-plugin-1-3-20-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2016-03-28"}],"impact":[]},{"uuid":"9008bbca9f6a51dabce187ea88a93a87d893343c9f3082812c9790c2c3b983ba","name":"Cloudflare [cloudflare] < 1.1.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-9841","name":"CVE-2017-9841","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-9841","description":"[en] Util\/PHP\/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a \"<?php \" substring, as demonstrated by an attack on a site with an exposed \/vendor folder, i.e., external access to the \/vendor\/phpunit\/phpunit\/src\/Util\/PHP\/eval-stdin.php URI.","date":"2017-06-27"},{"id":"e2d902e3-9a38-46d1-bd3c-59f591e3419a","name":"Multiple Plugins - Unauthenticated RCE via PHPUnit","link":"https:\/\/wpscan.com\/vulnerability\/e2d902e3-9a38-46d1-bd3c-59f591e3419a","description":"There was an Unauthenticated Remote Code Execution (RCE) vulnerability in PHPUnit, a widely used testing framework for PHP.\r\n\r\nThis vulnerability has been seen exploited in the wild.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"active","automatable":"yes","technical_impact":"total","kev":true,"kev_date":"2022-02-15"}}},{"uuid":"4f0464a5e19ee44a0c66f1b6342497ae686f5a608efba678481df848266b619c","name":"Cloudflare [cloudflare] < 1.3.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1e03fb0d-23a1-4451-bf8a-9b5dc9790b50","name":"CloudFlare &lt;= 1.3.20 - Authenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/1e03fb0d-23a1-4451-bf8a-9b5dc9790b50","description":"The Cloudflare WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"5ab24befe36a87d9674dcbfde6bee5e88f73392218a071d458913d2d32b48d95","name":"Cloudflare [cloudflare] < 1.3.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1674fd5d30f242cd9c1196dcd4154e705baacb9c","name":"Cloudflare < 1.3.21 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cloudflare\/cloudflare-1321-cross-site-scripting","description":"The Cloudflare plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.3.21 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2016-03-28"}],"impact":[]},{"uuid":"467923fa6c370c75cc4f0a2ca9e07e3cacf936712294a1df98b50fa5ee7671b1","name":"Cloudflare [cloudflare] < 4.12.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.12.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f80f3d55a529f665edfbad2a5f56160499fe067f","name":"Cloudflare <= 4.12.2 - Missing Authorization via initProxy","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cloudflare\/cloudflare-4122-missing-authorization-via-initproxy","description":"The Cloudflare plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'initProxy' function in versions up to and including 4.12.2. This makes it possible for authenticated attackers, with subscriber access and above, to send requests proxied through Cloudflare to arbitrary URLs.","date":"2024-01-04"},{"id":"CVE-2024-0212","name":"CVE-2024-0212","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0212","description":"[en] The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API.","date":"2024-01-29"},{"id":"e9c0792a97ceb8e33c7a7b5056c7f62f2c28606f","name":"WordPress  CloudFlare Plugin  <= 4.12.2 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cloudflare\/vulnerability\/wordpress-cloudflare-plugin-4-12-2-information-disclosure-of-cloudflare-api","description":"Update the WordPress CloudFlare plugin to the latest available version (at least 4.12.3).\nAn unknown person discovered and reported this Sensitive Data Exposure vulnerability in WordPress CloudFlare Plugin.  This vulnerability has been fixed in version 4.12.3.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"309356ef-d9b1-488c-a93e-3074a497214b","name":"Cloudflare &lt; 4.12.3 - Missing Authorization via initProxy","link":"https:\/\/wpscan.com\/vulnerability\/309356ef-d9b1-488c-a93e-3074a497214b","description":"The Cloudflare plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the &#039;initProxy&#039; function in versions up to and including 4.12.2. This makes it possible for authenticated attackers, with subscriber access and above, to send requests proxied through Cloudflare to arbitrary URLs.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1776153795"}