CVE · Medium

CVE-2026-25385 — URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.12.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-25385 URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.12.4 Server-Side Request Forgery (SSRF) Medium 5.5 < 1.12.4 1.12.4 2026-02-19

CVE-2026-25385

The URL Shortify plugin for WordPress contains a flaw in versions prior to 1.12.4 that allows authorized users with elevated permissions to craft malicious server-side requests on behalf of the website, potentially exposing sensitive data or disrupting internal systems. This vulnerability is triggered when an attacker exploits the plugin's ability to make arbitrary web requests from within the application context. The issue affects all plugin versions up to 1.12.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.