The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.
History

Tue, 25 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-03-28T05:00:02.401Z

Updated: 2025-03-25T18:20:13.467Z

Reserved: 2024-01-18T13:01:48.025Z

Link: CVE-2024-0677

cve-icon Vulnrichment

Updated: 2024-08-01T18:11:35.728Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-28T05:15:49.870

Modified: 2025-03-25T19:15:42.040

Link: CVE-2024-0677

cve-icon Redhat

No data.