Impact
The WPJAM Basic plugin for WordPress contains a Server‑Side Request Forgery flaw that allows an attacker to make the site request arbitrary URLs on the attacker’s behalf. This can expose internal resources or enable further exploitation, compromising confidentiality, integrity, or availability. The weakness is categorized as CWE‑918.
Affected Systems
Any WordPress installation that has the denishua WPJAM Basic plugin version 7.0 or earlier installed is affected. Site administrators and users who can trigger the plugin’s request functionality directly influence the risk.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 7.2 classifies the vulnerability as high severity. Based on the description, it is inferred that the attack would require access to the plugin’s request capability, either through a publicly reachable endpoint that accepts user‑authenticated use of the plugin’s interface. The exact exploitation path is not detailed in the advisory.
OpenCVE Enrichment