PixelYourSite Pro Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in the PixelYourSite Pro WordPress plugin, affecting all versions through 12.5.0.1. The vulnerability allows unauthenticated attackers to make web requests to arbitrary locations from the web application, potentially querying and modifying information from internal services. This blind SSRF only parses response bodies for YouTube and Vimeo patterns internally, without returning any data to the attacker.

Impact

Exploitation of this vulnerability could allow an attacker to access internal services and potentially manipulate information, depending on the service's configuration and the nature of the data.

Remediation

Users are advised to update the PixelYourSite Pro plugin to version 12.5.0.2 or a newer patched version.

Added: May 2, 2026, 6:19 AM
Updated: May 2, 2026, 6:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.4
exploitability
8.1
remediation
0.0
relevance
7.2
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.