CVE-2025-46511 MEDIUM

CVE-2025-46511: WordPress BeerXML Shortcode plugin <= 0.7.1 - Server Side Request Forgery (SSRF) Vulnerability

Vendor Derek Springer
Product BeerXML Shortcode
Weakness CWE-918 · SSRF
Published April 24, 2025
Last update April 28, 2026

CVSS base score

6.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Server-Side Request Forgery (SSRF) vulnerability in Derek Springer BeerXML Shortcode beerxml-shortcode allows Server Side Request Forgery.This issue affects BeerXML Shortcode: from n/a through <= 0.7.1.

Explanation of Vulnerability in Simple Terms

02Summary

The BeerXML Shortcode plugin for WordPress contains a server-side request forgery (SSRF) vulnerability that allows authenticated users to make the site send HTTP requests to internal or external systems on their behalf. An attacker with low-level site access can exploit this to access restricted resources, retrieve sensitive data, or interact with internal services. The vulnerability affects all versions up to 0.7.1.

What an attacker can do

03Attacker Capabilities

Make the site send HTTP requests to internal networks or external systems to access restricted resources or retrieve sensitive data.

Potential impact on your site

04Site Impact

Attackers with basic site access can probe your internal network, access cloud metadata services, or exfiltrate data via the site's outbound requests.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).

Key dates

06Disclosure timeline

April 24, 2025 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE