The Oxygen Theme for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability in versions up to and including 6.0.8. Exploitation of this flaw is possible via the 'laborator_calc_route' AJAX action, allowing unauthenticated attackers to initiate web requests to arbitrary locations from the WordPress server.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.