Impact
The vulnerability is a Server Side Request Forgery (SSRF) that allows an attacker to force the WordPress site to retrieve arbitrary URLs specified by the attacker. This can lead to exposure of sensitive internal resources, execution of internal network attacks, or data exfiltration. The weakness is categorized as CWE‑918.
Affected Systems
Oliver Campion:Display Remote Posts Block plugin from any version through 1.1.0.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity, while the EPSS score of less than 1 % reflects a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attacker must supply a malicious URL via the plugin’s interface, allowing the server to perform outbound HTTP requests to arbitrary hosts.
OpenCVE Enrichment
EUVD