Impact
The EmbedPress WordPress plugin prior to version 4.6.1 fails to validate user‐supplied URLs before initiating server‑side HTTP requests through unauthenticated endpoints. This flaw allows an attacker who does not possess site credentials to force the web server to make requests to arbitrary internal hosts or services that normal WordPress URL validation does not cover, resulting in a blind Server‑Side Request Forgery (CWE‑918). Consequently, an adversary could exfiltrate internal configuration data, trigger actions on internal services, or discover network topology without triggering any visible response to the user.
Affected Systems
Any WordPress site that has the EmbedPress plugin installed in a version older than 4.6.1 is vulnerable. The affected product is listed as "Unknown:EmbedPress" in vendor references, so the issue applies broadly to all installations of this plugin regardless of the site’s domain or hosting environment.
Risk and Exploitability
The vulnerability is exploitable by unauthenticated users with no prior access; the attack path requires only the ability to send a crafted HTTP request to the plugin’s endpoint. Because the vulnerability is blind, detection is difficult and there is no immediate externally observable failure. No EPSS score is available and the issue is not listed in CISA’s KEV catalog, but the inherent lack of authentication and the possibility of internal discovery make the risk high. The potential impact includes unauthorized data access, intrusions into internal services, or concealment of malicious activity.
OpenCVE Enrichment