{
 "id": "WPSEC-2026-0571",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0571/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0571/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0571/index.md",
 "title": "Parse.ly <= 3.24.1 - Server-Side Request Forgery via Remote Request Host Allowlist Bypass",
 "description": "The Parse.ly plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 3.13.0 up to, and including, 3.24.1. The plugin's http_request_host_is_external filter, which applies site-wide, treats any URL that begins with a Parse.ly service address as external. As a result, an HTTPS URL whose host name merely begins with a Parse.ly host name, but resolves to an internal IP address, passes WordPress's safe remote request checks. This makes it possible for unauthenticated attackers to make requests to internal services through features that fetch user-supplied URLs with WordPress's safe request functions, such as pingbacks when they are enabled.",
 "plugin": {
  "slug": "wp-parsely",
  "name": "Parse.ly",
  "full_name": "Parse.ly",
  "wordpress_org": "https://wordpress.org/plugins/wp-parsely/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-parsely/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-parsely"
 },
 "type": "SSRF",
 "cwe": [
  "CWE-918"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.4,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "3.13.0",
    "from_inclusive": true,
    "to": "3.24.2",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 3.13.0 before 3.24.2"
  ]
 },
 "introduced_in": "3.13.0",
 "fixed_in": "3.24.2",
 "remediation": "Update to 3.24.2 or later.",
 "fix_released": "2026-10-06T15:36:51+00:00",
 "published": "2026-10-07T15:58:04+00:00",
 "updated": "2026-10-06T19:48:15.044008+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0571/",
  "https://plugins.svn.wordpress.org/wp-parsely/tags/3.24.2/",
  "https://wordpress.org/plugins/wp-parsely/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-parsely",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}