automattic/jetpack-forms is vulnerable to Server-Side Request Forgery (SSRF)
43
Medium Risk
Affected versions of this package are vulnerable to Server-Side Request Forgery (SSRF) in the Forms webhooks feature due to inadequate URL validation, which allows attackers to craft webhook URLs that bypass restrictions and target internal networks or cloud metadata endpoints. By exploiting this, an attacker could submit malicious webhook URLs to initiate requests to sensitive internal services or access cloud instance metadata, potentially leading to data exposure, credential theft, or further network intrusion.
You are affected if you are using a version that falls within the vulnerable range.
automattic/jetpack-forms is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.21.0 - 7.2.0.
Upgrade the automattic/jetpack-forms library to a patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant