Post Affiliate Pro
cpe:2.3:a:qualityunit:post_affiliate_pro:*:*:*:*:wordpress:*:*
- <= 1.28.0
A server-side request forgery (SSRF) vulnerability has been identified in the Post Affiliate Pro plugin for WordPress, affecting all versions through 1.28.0. This vulnerability allows authenticated attackers with Administrator-level access to make arbitrary outbound requests from the application and read the response content. Exploitation of this vulnerability was confirmed by observing response data from an external Collaborator endpoint.
Exploitation of this vulnerability allows for server-side request forgery, enabling attackers to make unauthorized requests from the server where the application is hosted.
No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.