Executive brief
The Aotuman Grab WeChat Articles WordPress plugin allows authenticated users with subscriber privileges to perform server-side request forgery attacks. An attacker with subscriber-level access can trick the server into making requests to internal systems and services not normally accessible from the internet, potentially exposing sensitive data or facilitating further network compromise.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) vulnerability in the Aotuman Grab WeChat Articles WordPress plugin versions 2.0.1 and earlier. The plugin allows users with subscriber privileges to make the server perform HTTP requests to arbitrary internal or external systems. An authenticated attacker with subscriber-level account access can leverage this to probe internal services, exfiltrate data from services behind the firewall, or access cloud metadata endpoints. The vulnerability requires authentication at the subscriber privilege level but allows direct network-reachable exploitation once a valid subscriber account exists. No official patch is currently available; mitigation via a Patchstack rule has been issued to block exploitation attempts.
Affected products
- Aotuman Grab WeChat Articles <= 2.0.1
Timeline
- 2026-08-18: disclosed
- 2026-08-17: advisory: Patchstack advisory published