Impact
The vulnerability allows an attacker to cause the Complianz plugin to issue HTTP requests to arbitrary URLs chosen by the attacker. This Server Side Request Forgery (identified as CWE-918) can result in the exposure of internal network services, private data, or denial of service if the target system is overloaded. The impact is primarily confidentiality and availability of internal resources, without escalating privileges on the host.
Affected Systems
WordPress sites that use the Complianz plugin, versions up to and including 7.5.0. Any WordPress installation with the plugin beyond version 7.5.0 is considered not affected.
Risk and Exploitability
The CVSS score of 4.4 signifies moderate severity, while an EPSS score of less than 1% indicates a very low likelihood of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote; an attacker could trigger the plugin to fetch arbitrary external URLs through a crafted request, potentially revealing sensitive internal information. The exploit requires only the ability to influence the plugin’s request behavior, so no privileged access is necessary.
OpenCVE Enrichment