CVE-2025-8594: Unknown Pz-Linkcard

Low severity, CVSS 3.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.

Affected products

  • Unknown Pz-Linkcard: before 2.5.7 (fixed in 2.5.7)

Published 2025-10-14. Last modified 2026-10-08.