CVE-2024-23825
TablePress versions before 2.2.5 contain a server-side request forgery vulnerability in its table import functionality. When users provide URLs for importing tables, the plugin does not adequately validate the input, allowing attackers to direct requests to unintended network destinations and retrieve their responses. In cloud environments such as AWS, this flaw could enable attackers to make unauthorized requests to instance metadata APIs, potentially exposing sensitive internal data and credentials if the instance is misconfigured.
Based on public CVE data (MITRE/NVD).