Impact
The Visualizer WordPress plugin before version 4.0.6 allows a user‑supplied URL to be fetched server‑side without validating that it points to a safe address. Users with Contributor or higher privileges can supply a link‑local address such as those used by cloud instance‑metadata services. The fetched content is returned back to the attacker, making the SSRF non‑blind. An attacker can therefore retrieve sensitive data such as IAM credentials from the instance‑metadata endpoint when the WordPress site is hosted on cloud platforms.
Affected Systems
The affected product is the Visualizer Tables and Charts Manager WordPress plugin, versions earlier than 4.0.6. This includes any installation that has not applied the 4.0.6 update or later.
Risk and Exploitability
Because the vulnerability can be exploited by any user with Contributor access or higher, the attack surface is broad. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, yet the risk remains significant due to the potential exposure of cloud credentials. The non‑blind nature of the SSRF allows an attacker to confirm request success and read the returned data. An exploitable endpoint to instance‑metadata services is commonly accessible on cloud platforms, making exploitation highly feasible.
OpenCVE Enrichment