CyberRota Analysis
AI-GeneratedThe Greenshift WordPress plugin prior to version 13.2.0 is vulnerable due to inadequate validation of user-supplied URLs, enabling users with contributor-level access and higher to make server-side requests to arbitrary hosts and potentially read sensitive responses. This flaw poses a risk of information disclosure and could be exploited for further attacks. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.