CVE-2023-6991: Surniaulula Jsm File Get Contents() Shortcode

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow users with contributor role and above to perform SSRF attacks.

Affected products

  • Surniaulula Jsm File Get Contents() Shortcode: before 2.7.1 (fixed in 2.7.1)

Published 2024-01-15. Last modified 2026-06-17.