Description
WordPress Plugin Nelio AB Testing is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin Nelio AB Testing version 4.5.10 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.5.11 or latest
References
Related Vulnerabilities
WordPress Plugin WP Background Takeover Directory Traversal (4.1.4)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4285)
Microsoft SQL Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2003-0230)
Oracle Database Server CVE-2008-2587 Vulnerability (CVE-2008-2587)