PT-2025-51055 · WordPress · Emplibot+1

Published

2025-12-13

·

Updated

2025-12-13

·

CVE-2025-11970

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Emplibot – AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized plugin for WordPress versions through 1.0.9
Description The Emplibot plugin for WordPress is susceptible to Server-Side Request Forgery (SSRF). This allows authenticated attackers with Administrator-level access or higher to make web requests to arbitrary locations from the web application. This can be used to query and modify information from internal services. The issue occurs through the emplibot call webhook with error() and emplibot process zip data() functions.
Recommendations Update the Emplibot plugin to a version later than 1.0.9.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-11970

Affected Products

Emplibot
Wordpress