{"id":17454511,"date":"2024-02-26T21:34:32","date_gmt":"2024-02-26T21:34:32","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=topic&#038;p=17454511"},"modified":"2024-02-27T07:12:05","modified_gmt":"2024-02-27T07:12:05","slug":"server-side-request-forgery-2","status":"closed","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/server-side-request-forgery-2\/","title":{"rendered":"Server side request forgery"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hi, our security scanner is seeing the server side request forgery vulnerabilities on the Event Calendar wp-json URLs, such as <a href=\"https:\/\/www.sfari.org\/wp-json\/tribe\/events\/v1\/events\/\">https:\/\/www.sfari.org\/wp-json\/tribe\/events\/v1\/events\/<\/a> and <a href=\"https:\/\/www.simonsfoundation.org\/wp-json\/tribe\/events\/v1\/venues\/by-slug\/\">https:\/\/www.simonsfoundation.org\/wp-json\/tribe\/events\/v1\/venues\/by-slug\/<\/a> by POST. How can we fix this problem? Is this problem addressed already in your plugin? If so, which version?<\/p>\n","protected":false},"template":"","class_list":["post-17454511","topic","type-topic","status-closed","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/17454511","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/17454511\/revisions"}],"predecessor-version":[{"id":17454533,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/17454511\/revisions\/17454533"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=17454511"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}