CVE 3.8 LOW

Pz-LinkCard < 2.5.7 - Contributor+ SSRF_CVE-2025-8594

3.8 / 10
LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Description

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.

Basic Information

ID CVE-2025-8594
Source WPScan
Published Oct 14, 2025 at 06:00
Modified Oct 14, 2025 at 13:39

Affected Product

Vendor Unknown
Product Pz-LinkCard
Affected Versions Unknown Pz-LinkCard 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.