PT-2026-51669 · WordPress · Wp Meta Seo
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Meta SEO versions prior to 4.5.19
Description
The plugin is susceptible to Server-Side Request Forgery (SSRF), a flaw that allows an attacker to induce the server-side application to make requests to an unintended location. Authenticated users with contributor-level access or higher can exploit the
new link parameter to send web requests to arbitrary locations from the application, potentially querying or modifying internal services. The HTTP response status of these requests is returned in the AJAX JSON response as status code, creating an enumeration oracle that can be used to probe internal hosts and cloud metadata services.Recommendations
Update the plugin to version 4.5.19 or later.
As a temporary mitigation, restrict access to the
new link parameter for users with contributor-level permissions.Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Meta Seo