What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Electrician - Electrical Service WordPress electrician allows Server Side Request Forgery.This issue affects Electrician - Electrical Service WordPress: from n/a through <= 5.6.
Explanation of Vulnerability in Simple Terms
02Summary
The Electrician plugin for WordPress contains a server-side request forgery vulnerability that allows an attacker to make the site send HTTP requests to internal or external systems on the attacker's behalf. The vulnerability affects versions 5.6 and earlier. An attacker can exploit this to access internal services, retrieve sensitive data, or interact with external systems without direct access. Site administrators should update to a version newer than 5.6.
What an attacker can do
03Attacker Capabilities
Make your site send HTTP requests to internal systems or external servers to retrieve data or perform actions.
Potential impact on your site
04Site Impact
Attackers could access internal services, retrieve sensitive information, or interact with external systems via your site.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
January 22, 2026
CVE published
April 28, 2026
Record updated