CVE-2014-9292: Jrss Widget Project Jrss Widget
Medium severity, CVSS 5.8. EPSS: 1.9% chance of exploitation in the next 30 days.
Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress allows remote attackers to trigger outbound requests and enumerate open ports via the url parameter.
Affected products
- Jrss Widget Project Jrss Widget: up to and including 1.2
Published 2014-12-05. Last modified 2026-06-17.