Description
It was determined that the web application performs a server-side rendering/processing of a user supplied data in insecure way. An unauthenticated attacker could use this vulnerability to send requests to restricted services. Also, in certain cases, it may be possible to read arbitrary local files of the system.
Remediation
Sanitize user's data
References
Related Vulnerabilities
WordPress Plugin HTTP Headers Multiple Vulnerabilities (1.9.1)
WordPress Plugin All in One Social Lite Server-Side Request Forgery (1.0)
WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-17669)
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress Multiple Vulnerabilities (3.3.0)