PixelYourSite Pro Server-Side Request Forgery Vulnerability
Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in the PixelYourSite Pro WordPress plugin, affecting all versions through 12.5.0.1. The vulnerability allows unauthenticated attackers to make web requests to arbitrary locations from the web application, potentially querying and modifying information from internal services. This blind SSRF only parses response bodies for YouTube and Vimeo patterns internally, without returning any data to the attacker.
Impact
Exploitation of this vulnerability could allow an attacker to access internal services and potentially manipulate information, depending on the service's configuration and the nature of the data.
Remediation
Users are advised to update the PixelYourSite Pro plugin to version 12.5.0.2 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
