Input validation vulnerability in JSM file_get_contents() Shortcode 2.7.0

The JSM file_get_contents() Shortcode plugin for WordPress is vulnerable to a type of attack known as Server-Side Request Forgery. This type of attack is possible in versions of the plugin up to, and including, 2.7.0, and can be accessed using the wpfgc shortcode. If an attacker has the right permissions (at least contributor level) they can make web requests from the WordPress application to other locations. This can be used to query and modify information from internal services.

Detected in:

JSM file_get_contents() Shortcode open vulnerable versions: >= * <= 2.7.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.