Description
The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow users with contributor role and above to perform SSRF attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-59183 | The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow users with contributor role and above to perform SSRF attacks. |
References
History
Wed, 23 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-11T16:42:03.110Z
Reserved: 2023-12-20T10:11:55.989Z
Link: CVE-2023-6991
Updated: 2024-08-02T08:50:06.847Z
Status : Modified
Published: 2024-01-15T16:15:12.743
Modified: 2025-06-11T17:15:40.233
Link: CVE-2023-6991
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD