# Parse.ly <= 3.24.1 - Server-Side Request Forgery via Remote Request Host Allowlist Bypass

- **ID:** WPSEC-2026-0571
- **Plugin:** Parse.ly (`wp-parsely`), https://wordpress.org/plugins/wp-parsely/
- **Affected versions:** from 3.13.0 before 3.24.2
- **Fixed in:** 3.24.2 (Update to 3.24.2 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-918
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-parsely
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0571/

## Description

The Parse.ly plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 3.13.0 up to, and including, 3.24.1. The plugin's http_request_host_is_external filter, which applies site-wide, treats any URL that begins with a Parse.ly service address as external. As a result, an HTTPS URL whose host name merely begins with a Parse.ly host name, but resolves to an internal IP address, passes WordPress's safe remote request checks. This makes it possible for unauthenticated attackers to make requests to internal services through features that fetch user-supplied URLs with WordPress's safe request functions, such as pingbacks when they are enabled.

## References

- https://wpsec.com/vuln/WPSEC-2026-0571/
- https://plugins.svn.wordpress.org/wp-parsely/tags/3.24.2/
- https://wordpress.org/plugins/wp-parsely/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0571/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
