Intel

AIKIDO-2026-10053

automattic/jetpack-forms is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

43

Medium Risk

This Affects:

PHPautomattic/jetpack-forms
6.21.0 - 7.2.0
Fixed in 7.3.0

TL;DR

Affected versions of this package are vulnerable to Server-Side Request Forgery (SSRF) in the Forms webhooks feature due to inadequate URL validation, which allows attackers to craft webhook URLs that bypass restrictions and target internal networks or cloud metadata endpoints. By exploiting this, an attacker could submit malicious webhook URLs to initiate requests to sensitive internal services or access cloud instance metadata, potentially leading to data exposure, credential theft, or further network intrusion.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

automattic/jetpack-forms is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.21.0 - 7.2.0.

How to fix this

Upgrade the automattic/jetpack-forms library to a patch version.