WordPress Plugin Vulnerabilities

Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery via JSON Import

Description

The plugin does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata endpoints. As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.

Proof of Concept

Affects Plugins

Fixed in 4.0.6

References

Classification

Type
SSRF
OWASP top 10
CWE

Miscellaneous

Original Researcher
creeper_kirby
Submitter
creeper_kirby
Verified
Yes

Timeline

Publicly Published
2026-07-27 (about 8 days ago)
Added
2026-07-27 (about 7 days ago)
Last Updated
2026-07-27 (about 7 days ago)

Other