Impact
The Fediverse Embeds WordPress plugin before version 1.5.8 does not validate the destination of a server‑side request performed by an unauthenticated site‑info endpoint. This flaw allows anonymous users the server to fetch an arbitrary internal or private‑network URL and return the parsed page metadata. The result is a server‑side request forgery (CWE‑918) that exposes internal network information to any visitor.
Affected Systems
plugin installed and running a version older than 1.5.8 is affected. The site‑info endpoint is publicly accessible and requires no authentication, meaning all visitors can trigger the vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1 % shows a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, so no widespread exploitation is known. Attackers can use the endpoint to probe internal hosts and harvest metadata from private URLs, though the impact is limited to the data returned by the request.
OpenCVE Enrichment