Post Affiliate Pro Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in the Post Affiliate Pro plugin for WordPress, affecting all versions through 1.28.0. This vulnerability allows authenticated attackers with Administrator-level access to make arbitrary outbound requests from the application and read the response content. Exploitation of this vulnerability was confirmed by observing response data from an external Collaborator endpoint.

Impact

Exploitation of this vulnerability allows for server-side request forgery, enabling attackers to make unauthorized requests from the server where the application is hosted.

Remediation

No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.

Added: Mar 21, 2026, 4:29 AM
Updated: Mar 21, 2026, 4:29 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
5.0
remediation
0.0
relevance
4.2
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.