Impact
The ProSolution WP Client WordPress plugin fails to validate a user‑supplied URL and does not enforce capability or nonce checks before performing a server‑side HTTP request. This flaw allows any authenticated user with subscriber level access to cause the site to issue arbitrary requests to internal hosts and services, including the ability to choose method, headers and body. The consequence is a Server‑Side Request Forgery that can expose internal resources, leak sensitive data, or facilitate further attacks such as port scanning or exploitation of internal services, thereby compromising confidentiality and integrity of the network.
Affected Systems
The vulnerability affects all installations of the ProSolution WP Client plugin with a version number lower than 2.0.9 running on WordPress. No other vendors or products are listed as impacted.
Risk and Exploitability
Exploitability is enabled for any authenticated subscriber; no additional privileges are required beyond the normal WordPress authentication mechanism. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. CVSS data is not provided in the public description, but the lack of validation and authorization controls indicates a high severity risk if exploited. Attackers could leverage the flaw to reach internal systems and potentially pivot further within the network.
OpenCVE Enrichment