CVE-2023-36679
The Spectra Legacy plugin for WordPress versions before 2.6.7 contains a Server Side Request Forgery vulnerability that allows attackers to manipulate the affected website into making HTTP requests to arbitrary destinations specified by the attacker. An attacker could exploit this flaw to probe internal services running on the server or connected systems and potentially access sensitive information from those services. The vulnerability was discovered by Rafie Muhammad of Patchstack and has been patched in version 2.6.7 and later.
Based on public CVE data (MITRE/NVD).