Impact
An unauthenticated Server Side Request Forgery (SSRF) flaw exists in versions of the WordPress Paid Member Subscriptions plugin up to 3.0.4. The vulnerability allows an attacker to trigger the plugin to perform arbitrary HTTP or HTTPS requests from the web server, potentially exposing internal network resources or sensitive data. It is classified as CWE‑918, a flaw that permits request forging without authentication.
Affected Systems
WordPress sites that have the Cozmoslabs Paid Member Subscriptions plugin at version 3.0. or earlier are vulnerable. The issue affects all installations of these versions, regardless of other plugins or configurations.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while the EPSS score of less than 1 % reflects a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can send a request to a public endpoint of the plugin that accepts a URL parameter and, without authentication, cause the site to fetch arbitrary URLs, which could be used to probe internal services or exfiltrate data. Exact attack paths are unspecified, but the SSRF nature suggests any publicly reachable endpoint that forwards user‑controlled URLs is a potential vector.
OpenCVE Enrichment