Impact
The SmartAIPress WordPress plugin through version 1.2.0 fails to perform a capability check on the smartaipress_openai_upload_and_set_featured_image AJAX action and does not validate the URL that a client supplies before fetching it server‑side. A user who holds the Subscriber role or any higher privilege can send a crafted request that causes WordPress to retrieve an arbitrary internal or external URL and read the response content. This allows the attacker to read server‑side responses, effectively creating a full‑read Server‑Side Request Forgery vulnerability that can expose data beyond the website’s public scope.
Affected Systems
All WordPress installations that have SmartAIPress version 1.2.0 or earlier enabled are affected. The flaw applies to any site where the plugin is active and a user is assigned the Subscriber role or higher. No additional WordPress core or theme prerequisites are identified.
Risk and Exploitability
Because the vulnerability can be exploited via a simple AJAX request from any authenticated Subscriber user, the risk of exploitation is high in environments where such accounts exist. No CVSS score is provided, and the EPSS score is not available, so the exact exploitation likelihood cannot be quantified. The flaw is not listed in the CISA KEV catalog, but its public availability and low technical barrier make it a significant concern.
OpenCVE Enrichment