CVE-2020-28977 | Canto Plugin 1.3.0 on WordPress /includes/lib/get.php subdomain server-side request forgery (EDB-49189)
A vulnerability classified as critical was found in Canto Plugin 1.3.0 on WordPress. Affected by this vulnerability is an unknown functionality of the file /includes/lib/get.php. The manipulation of the argument subdomain leads to server-side request forgery.
This vulnerability is known as CVE-2020-28977. The attack can only be done within the local network. Furthermore, there is an exploit available.