Server-Side Request Forgery in Emplibot Plugin for WordPress
CVE-2025-11970

4.4MEDIUM

What is CVE-2025-11970?

The Emplibot plugin for WordPress, designed for automated content creation and SEO optimization, is susceptible to Server-Side Request Forgery (SSRF). This vulnerability exists in the plugin's core functions, allowing authenticated users with Administrator-level access to send requests to arbitrary locations. This can be exploited to access internal services, potentially compromising sensitive information.

Affected Version(s)

Emplibot – AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized | Fully Automated * <= 1.0.9

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.