Impact
The plugin contains a subscriber‑level SSRF flaw that permits an attacker to instruct the WordPress installation to perform arbitrary HTTP or HTTPS requests to any target, including internal network services. This weakness can lead to data disclosure, credential harvesting or launching further attacks against internal components. The flaw is a classic web request forgery identified as CWE‑918.
Affected Systems
WordPress plugin "[Aotuman] Grab WeChat Articles" by apoyl with versions 2.0.1 and earlier is vulnerable. The issue exists in the plugin’s request handling code that accepts external URLs from untrusted input.
Risk and Exploitability
The CVSS score of 6.0 indicates a medium risk level. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the probability of exploit is uncertain but potentially significant in environments that allow the plugin to process untrusted data. The likely attack vector is through the plugin’s subscriber interface, where an attacker can supply a crafted URL to trigger the SSRF.
OpenCVE Enrichment