CVE-2014-9292: Jrss Widget Project Jrss Widget

Medium severity, CVSS 5.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress allows remote attackers to trigger outbound requests and enumerate open ports via the url parameter.

Affected products

Published 2014-12-05. Last modified 2026-06-17.