MEDIUM
minnur
CVE published 2026-01-07
CVE-2025-49335
A Server-Side Request Forgery (SSRF) vulnerability exists in the External Media plugin for WordPress, affecting versions from n/a through 1.0.36. This issue allows for Server Side Request Forgery. The vulnerability can lead to unauthorized requests or bypass of security controls, potentially impacting systems using the plugin. Defenders should assess potential exposure and prioritize verification and reme [truncated]