Impact
The EmbedPress WordPress plugin prior to version 4.6.1 fails to validate user‑supplied URLs before initiating server‑side HTTP requests through unauthenticated endpoints. This flaw allows an attacker who does not possess site credentials to force the web server to make requests to arbitrary internal hosts or services that normal WordPress URL validation does not cover, resulting in a blind Server‑Side Request Forgery (CWE‑918). Consequently, an adversary could exfiltrate internal configuration data, trigger actions on internal services, or discover network topology without triggering any visible response to the user.
Affected Systems
Any WordPress site that has the EmbedPress plugin installed in a version older than 4.6.1 is vulnerable. The affected product is listed as "Unknown:EmbedPress" in vendor references, so the issue applies broadly to all installations of this plugin regardless of the site’s domain or hosting environment.
Risk and Exploitability
Based on the description, the vulnerability can be exploited by unauthenticated users; the likely attack vector is sending a crafted HTTP request to the plugin’s unauthenticated endpoint. Because the vulnerability is blind, detection is difficult and there is no immediate externally observable failure. The EPSS score is < 1% and the CVSS score is 5.8, indicating moderate severity; the issue is not listed in CISA’s KEV catalog, but the inherent lack of authentication and the possibility of internal discovery make the risk significant. The potential impact includes unauthorized data access, intrusions into internal services, or concealment of malicious activity.
OpenCVE Enrichment