Description
The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
Any version before 2.5.7
Credits
Dmitrii Ignatyev
WPScan
References
wpscan.com/...rability/17104590-d84e-41b7-83ac-9b15fcfb537a/