Impact
An SSRF flaw in the WPO365 plugin allows an attacker to trick the plugin into issuing requests to arbitrary URLs. This capability can expose internal network resources or transfer sensitive data to an attacker-controlled endpoint, thereby compromising confidentiality and potentially enabling further attacks such as credential theft or service disruption.
Affected Systems
The vulnerability affects the WordPress WPO365 login plugin made by Marco van Wieren, versions up to and including 40.0. If the plugin is installed on a WordPress site, any user able to interact with the plugin’s input fields could exploit the flaw.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate risk, and an EPSS score below 1% suggests exploitation is unlikely in the near term. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require the attacker to supply a malicious request parameter to the plugin, which the plugin then forwards to a target URL, typically originating from within the web application environment.
OpenCVE Enrichment