vulnerability

WordPress Plugin: leadin: CVE-2022-1239: Server-Side Request Forgery (SSRF)

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Apr 11, 2022
Added
May 15, 2025
Modified
Jun 24, 2025

Description

The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default contributor and above) to perform SSRF attacks

Solution

leadin-plugin-cve-2022-1239
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.