CyberRota Analysis
AI-GeneratedThe ProSolution WP Client plugin for WordPress versions prior to 2.0.9 is vulnerable due to insufficient validation of user-supplied URLs and a lack of capability checks, enabling authenticated users to initiate arbitrary server-side HTTP requests. This flaw could lead to unauthorized access to internal services and data, potentially allowing attackers to manipulate requests with custom methods and payloads. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the site issue arbitrary requests to internal hosts and services, including requests with an attacker-chosen method, headers and body.