The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.
History

Tue, 01 Apr 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Popozure
Popozure pz-linkcard
Weaknesses CWE-918
CPEs cpe:2.3:a:popozure:pz-linkcard:*:*:*:*:*:wordpress:*:*
Vendors & Products Popozure
Popozure pz-linkcard

Tue, 25 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-03-25T18:20:13.467Z

Reserved: 2024-01-18T13:01:48.025Z

Link: CVE-2024-0677

cve-icon Vulnrichment

Updated: 2024-08-01T18:11:35.728Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-28T05:15:49.870

Modified: 2025-04-01T18:28:24.883

Link: CVE-2024-0677

cve-icon Redhat

No data.