Orbit Fox WordPress Plugin Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in the Orbit Fox WordPress plugin, specifically in versions prior to 3.0.2. The vulnerability arises because the plugin's stock photo import feature does not restrict the URLs that users can submit, allowing for arbitrary URL input. This lack of validation enables users to force the server to access any URL of their choice.

Impact

Exploitation of this vulnerability allows for server-side request forgery, where an attacker can manipulate the server into making requests to unintended locations, potentially leading to the exposure of internal resources or information.

Reproduction

To reproduce this vulnerability, create a post in WordPress and click the camera icon to access the stock photo import feature. Intercept the request to 'wp-admin/admin-ajax.php' and replace the URL parameter with a URL of choice, such as one from Webhook.site or an internal URL. Once the request is sent, the server will access the substituted URL, demonstrating the SSRF vulnerability.

Remediation

Users are advised to update the Orbit Fox WordPress plugin to version 3.0.2 or later.

Added: Oct 24, 2025, 6:20 AM
Updated: Oct 24, 2025, 6:20 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
6.8
remediation
7.7
relevance
0.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.