Friday, July 31, 2020

oEmbed API remote attackers to read arbitrary files

http://yousite.com.com/wp-json/oembed/1.0/embed?url=http%3A%2F%2Fyoursite.com
IP: 52.143.159.22 Hostname: 52.143.159.22

This looks like an attempt to discover usernames via the oEmbed API.

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.