Zapier for WordPress Server-Side Request Forgery Vulnerability

Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Zapier for WordPress plugin, affecting all versions through 1.5.1. The vulnerability arises in the updated_user() function, allowing authenticated attackers with Subscriber-level access or higher to make web requests to arbitrary locations. This could be exploited to query and modify information from internal services.

Impact

Exploitation of this vulnerability allows for blind Server-Side Request Forgery, where an attacker can make requests from the server to internal or external services, potentially leading to unauthorized information disclosure or modification.

Reproduction

To reproduce this vulnerability, an authenticated user with Subscriber-level access or higher can trigger the updated_user() function. This can be done by updating a user profile, which will invoke the function and send a request to a specified endpoint. The request can be directed to an internal service, allowing the attacker to query or modify information.

Remediation

Users are advised to update the Zapier for WordPress plugin to version 1.5.2 or later, where this vulnerability has been patched.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
6.3
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.