Server-Side Request Forgery in PixelYourSite Pro Plugin for WordPress
CVE-2026-7049

7.2HIGH

What is CVE-2026-7049?

The PixelYourSite Pro plugin for WordPress contains a vulnerability allowing unauthenticated attackers to exploit server-side request forgery (SSRF) in versions up to 12.5.0.1. By leveraging the scan_video function, malicious actors can send HTTP requests to internal services, potentially allowing them to query or modify sensitive information. This vulnerability is classified as blind SSRF since any response data retrieved is not returned to the attacker but is only parsed internally for specific patterns related to platforms like YouTube and Vimeo.

Affected Version(s)

PixelYourSite Pro – Your smart PIXEL (TAG) Manager 0 <= 12.5.0.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Osvaldo Noe Gonzalez Del Rio
.