Local Syndication <= 1.5a - Authenticated (Contributor+) Server-Side Request Forgery via Shortcode
mediumThe Local Syndication plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5a via the `url` parameter in the `[syndicate_local]` shortcode. This is due to the use of `wp_remote_get()` instead of `wp_safe_remote_get()` which lacks protections against requests to inter...
- CVSS:
- 6.4
- Affected:
- up to 1.5a
- Fix:
- No patched version reported
- Disclosed:
- Nov 17, 2025