{"id":"CVE-2024-1978","summary":"Friends \u003c= 2.8.5 - Authenticated (Admin+) Blind Server-Side Request Forgery","details":"The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.5 via the discover_available_feeds function. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.","modified":"2026-08-12T03:51:12.779926688Z","published":"2024-02-29T06:47:57.113Z","database_specific":{"cna_assigner":"Wordfence","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1978.json"},"references":[{"type":"WEB","url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3036987%40friends&new=3036987%40friends&sfp_email=&sfph_mail="},{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/72e1fbce-86ae-4518-a613-7c322193acf4?source=cve"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1978.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1978"},{"type":"FIX","url":"https://github.com/akirk/friends/pull/290"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/akirk/friends","events":[{"introduced":"0"},{"fixed":"d18e821ba35c734923d533bd426b585192e9a331"}],"database_specific":{"cpe":"cpe:2.3:a:alex.kirk:friends:*:*:*:*:*:wordpress:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.8.5"},{"fixed":"2.8.6"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["2.8.5","2.8.4","2.8.3","2.8.2","2.8.1","2.8.0","2.7.9","2.7.8","2.7.7","2.7.6","2.7.5","2.7.4","2.7.3","2.7.2","2.7.1","2.7.0","2.6.0","2.5.3","2.5.2","2.5.1","2.5.0","2.4.0","2.3.1","2.3.0","2.2.0","2.1.3","2.1.2","2.1.1","2.1.0","2.0.2","2.0.1","2.0.0","1.9.1","1.9.0","1.8.5","1.8.4","1.8.3","1.8.2","1.8.1","1.8.0","1.5.9","1.5.8","1.5.7","1.5.6","1.5.5","1.5.4","1.5.3","1.5.2","1.5.1","1.4.4","1.4.3","1.4.2","1.4.1","1.1","1.02","1.01","1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-1978.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"}]}