Impact
The Fediverse Embeds WordPress plugin versions prior to 1.5.proxy endpoint, allowing unauthenticated users to instruct the media‑proxy to fetch any URL. This flaw enables a full‑read Server‑Side Request Forgery (CWE‑918) and effectively turns the site into an open proxy, exposing internal and private‑network resources to remote observers.
Affected Systems
The vulnerable product is the Fediverse Embeds plugin for WordPress, with all releases before 1.5.8. No further variant or vendor information is present.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker can supply any URL, including internal or private‑network addresses, and retrieve the response body, thereby reading sensitive internal data.
OpenCVE Enrichment