Description
WordPress Plugin PhonePe Payment Solutions is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin PhonePe Payment Solutions version 1.0.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.0 or latest
References
Related Vulnerabilities
WordPress Plugin Zingiri Web Shop 'wpabspath' Parameter Remote File Include (2.2.0)
Ruby Use of Externally-Controlled Format String Vulnerability (CVE-2018-8778)
Apache Tomcat Insufficiently Protected Credentials Vulnerability (CVE-2019-12418)
WordPress Plugin SEO by Squirrly SEO SQL Injection (12.3.19)
WordPress Plugin jQuery Reply to Comment Cross-Site Request Forgery (1.31)