CVE-2024-38728 HIGH

CVE-2024-38728: WordPress Seraphinite Post .DOCX Source plugin <= 2.16.9 - Server Side Request Forgery (SSRF) vulnerability

Vendor Seraphinite Solutions
Product Seraphinite Post .DOCX Source
Weakness CWE-918 · SSRF
Published July 22, 2024
Last update April 28, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9.

Explanation of Vulnerability in Simple Terms

02Summary

Seraphinite Post .DOCX Source versions up to 2.16.9 contain a server-side request forgery vulnerability. An attacker can make the affected component send HTTP requests to internal or external systems on behalf of the server. This could expose internal services, retrieve sensitive data, or interact with systems the attacker cannot reach directly. No authentication is required.

What an attacker can do

03Attacker Capabilities

Make the server send requests to internal systems or external URLs to retrieve data or interact with services.

Potential impact on your site

04Site Impact

Attackers can probe your internal network, access internal services, or exfiltrate data through the server.

Conditions required to exploit

05Prerequisites

Network access to the vulnerable component; no authentication or user interaction required.

Key dates

06Disclosure timeline

July 22, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE