What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Derek Springer BeerXML Shortcode beerxml-shortcode allows Server Side Request Forgery.This issue affects BeerXML Shortcode: from n/a through <= 0.7.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in Derek Springer BeerXML Shortcode beerxml-shortcode allows Server Side Request Forgery.This issue affects BeerXML Shortcode: from n/a through <= 0.7.1.
Explanation of Vulnerability in Simple Terms
The BeerXML Shortcode plugin for WordPress contains a server-side request forgery (SSRF) vulnerability that allows authenticated users to make the site send HTTP requests to internal or external systems on their behalf. An attacker with low-level site access can exploit this to access restricted resources, retrieve sensitive data, or interact with internal services. The vulnerability affects all versions up to 0.7.1.
What an attacker can do
Make the site send HTTP requests to internal networks or external systems to access restricted resources or retrieve sensitive data.
Potential impact on your site
Attackers with basic site access can probe your internal network, access cloud metadata services, or exfiltrate data via the site's outbound requests.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities