CVE-2014-8749: Ait-Pro Bulletproof Security
Medium severity, CVSS 5.0. EPSS: 1.9% chance of exploitation in the next 30 days.
Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.
Affected products
- Ait-Pro Bulletproof Security: up to and including .51
Published 2014-12-01. Last modified 2026-06-17.