Junglewise Threat Intelligence

CVE-2026-57372: denishua WPJAM Basic SSRF in WordPress plugin

CVE-2026-57372 · Severity: high · CVSS 7.2 · Published 2026-07-13

Executive brief

WPJAM Basic, a popular WordPress optimization plugin, is vulnerable to a security flaw that allows unauthorized requests to be sent from the web server. An attacker could exploit this to probe internal network services that are not normally accessible from the internet or to mask the origin of malicious traffic. This could lead to the exposure of sensitive internal data or unauthorized access to other systems within the corporate network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the denishua WPJAM Basic plugin for WordPress (versions <= 7.0). The vulnerability (CWE-918) allows an unauthenticated remote attacker to induce the server to make requests to arbitrary domains or internal network resources. This occurs due to insufficient validation of user-supplied URLs before the plugin performs a server-side request. Attackers can leverage this to bypass firewalls, scan internal networks, or access metadata services in cloud environments. The issue is resolved in version 7.0.1.

Affected products

  • denishua WPJAM Basic <= 7.0

Timeline

  • 2026-04-30: disclosed: Reported by she11f to Patchstack
  • 2026-07-07: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE record
  • 2026-07-07: patched: Version 7.0.1 released to address the vulnerability

References