Vulnerabilities / Parse.ly / WPSEC-2026-0571

Parse.ly <= 3.24.1 - Server-Side Request Forgery via Remote Request Host Allowlist Bypass

Medium 5.4 CWE-918Fixed in 3.24.2
ID
WPSEC-2026-0571
Plugin
Parse.ly (wp-parsely)
Affected
from 3.13.0 before 3.24.2
Remediation
Update to 3.24.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-918
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Parse.ly on WPSec AttackSurface
Fix released
Published

Description

The Parse.ly plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 3.13.0 up to, and including, 3.24.1. The plugin's http_request_host_is_external filter, which applies site-wide, treats any URL that begins with a Parse.ly service address as external. As a result, an HTTPS URL whose host name merely begins with a Parse.ly host name, but resolves to an internal IP address, passes WordPress's safe remote request checks. This makes it possible for unauthenticated attackers to make requests to internal services through features that fetch user-supplied URLs with WordPress's safe request functions, such as pingbacks when they are enabled.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0