WordPress Plugin Vulnerabilities

ProSolution WP Client < 2.0.9 - Subscriber+ SSRF via proSol_url_validate

Description

The plugin does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the site issue arbitrary requests to internal hosts and services, including requests with an attacker-chosen method, headers and body.

Proof of Concept

Affects Plugins

References

Classification

Type
SSRF
OWASP top 10
CWE

Miscellaneous

Original Researcher
Nir Yehoshua
Submitter
Nir Yehoshua
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-10 (about 3 days ago)
Added
2026-08-10 (about 2 days ago)
Last Updated
2026-08-10 (about 2 days ago)

Other