Impact
The vulnerability permits a malicious actor who can influence plugin requests to force the host server to make HTTP calls to internal or external addresses. This can expose sensitive internal endpoints or exfiltrate data, potentially enabling further exploitation. The weakness is identified as CWE-918.
Affected Systems
The issue exists in versions of the Vehica Core WordPress plugin from TangibleWP up to and including 1.0.104. Only the plugin itself is affected; the WordPress core remains unaffected.
Risk and Exploitability
The CVSS score of 6 indicates moderate risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits. Exploitation requires that an attacker can send crafted requests to the plugin endpoint, and the server will follow them. The scope is confined to the host where the WordPress site runs.
OpenCVE Enrichment