Junglewise Threat Intelligence

CVE-2026-5737: Independent Analytics WordPress plugin SSRF in favicon fetcher

CVE-2026-5737 · Severity: medium · CVSS 6.5 · Published 2026-05-28

Executive brief

Independent Analytics is a WordPress plugin used to track website visitor data. A security flaw allows unauthenticated attackers to force the website's server to make unauthorized requests to other internal or external systems. This could lead to the exposure of sensitive internal information or allow attackers to probe the local network behind the website's firewall.

Technical details

The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) due to an insecure public tracking route at /wp-json/iawp/search. This route accepts attacker-controlled 'referrer_url' values when a valid signature is provided; however, the signature validation is flawed as signatures are exposed in public JavaScript and use static salts. These injected URLs are later processed by a scheduled favicon fetcher that uses raw cURL functions without SSRF protections, such as private network filtering or the use of WordPress's 'wp_safe_remote_*' functions. An unauthenticated attacker can exploit this to perform internal port scanning or access sensitive metadata services from the hosting server.

Affected products

  • Independent Analytics Independent Analytics up to, and including, 2.14.9

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References