CVE-2023-6991: Surniaulula Jsm File Get Contents() Shortcode
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow users with contributor role and above to perform SSRF attacks.
Affected products
- Surniaulula Jsm File Get Contents() Shortcode: before 2.7.1 (fixed in 2.7.1)
Published 2024-01-15. Last modified 2026-06-17.