疑似Oday
The Jetpack WordPress plugin exposes an endpoint that fetches external URLs provided via the 'urls' parameter to retrieve Twitter (X) card descriptions/metadata. This allows unauthenticated SSRF, enabling attackers to force the server to request attacker-controlled URLs
id: wp-jetpack-ssrf
info:
name: Wordpress Jetpack plugin - Server Side Request Forgery
author:
...