Wordpress Alert: Server-side request forgery in import tools

An importer downloads content from an unrestricted address. Internal services may be reached through the WordPress host.

What it looks like

An importer downloads content from an unrestricted address.

Why it matters

Internal services may be reached through the WordPress host.

What to check

Audit remote-fetch features and destination validation.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP server-side request forgery guidance.