Surniaulula develops a WordPress plugin providing file-retrieval functionality through a shortcode interface, with the observed vulnerability exposure centered on server-side request forgery in the jsm_file_get_contents() implementation. This represents a modestly scoped plugin surface characterized by network-request handling weaknesses. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Surniaulula over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6991HIGH The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow users with | Jan 15, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Surniaulula.
Media articles that mention a CVE ID that affects a product developed by Surniaulula — matched by CVE ID, not by vendor name.