aoa-downloadable WordPress Plugin Unauthenticated Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in the aoa-downloadable WordPress plugin, affecting versions through 0.1.0. The vulnerability arises from a lack of authorization and authentication for requests made to the download.php endpoint, allowing unauthenticated users to send requests to arbitrary URLs.

Impact

Exploitation of this vulnerability allows for unauthenticated server-side request forgery, where an attacker can make the server send requests to internal or external resources, potentially leading to the exposure of sensitive information or interaction with internal services.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.