Server-Side Request Forgery Vulnerability in Youzify Plugin by Youzify
CVE-2025-69014

4.9MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
30 December 2025

What is CVE-2025-69014?

The Youzify Plugin contains a Server-Side Request Forgery (SSRF) vulnerability that could allow an attacker to send unauthorized requests to internal services on behalf of the server. This issue impacts versions of the Youzify Plugin up to 1.3.5, potentially exposing sensitive information or leading to further exploitation.

Affected Version(s)

Youzify 0 <= 1.3.7

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NumeX | Patchstack Bug Bounty Program
.