Description
Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request Forgery.This issue affects nK Themes Helper: from n/a through <= 1.7.9.
Published: 2026-01-08
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Server‑Side Request Forgery flaw exists in the nK Themes Helper WordPress plugin for versions up to 1.7.9. The vulnerability allows an attacker to coerce the plugin into making arbitrary HTTP requests to any URL specified by the attacker. This can result in the retrieval of sensitive information from internal or remote systems, or the triggering of actions on those systems via the plugin’s request logic.

Affected Systems

WordPress sites that have the nK Themes Helper plugin installed with a version less than or equal to 1.7.9 are affected. The exact release range is "n/a through <= 1.7.9"; site owners using any version of the plugin at or below that cutoff should review their installations.

Risk and Exploitability

The CVSS vector scores the flaw at 6.4, which represents a medium severity attack. The EPSS score of < 1% indicates that, as of the last update, exploit attempts are expected to be rare. The flaw is not listed in the CISA KEV catalog. The likely attack surface is the plugin’s request handling endpoint, and an attacker would need a way to supply a target URL – either by exploiting an authenticated configuration page or by tricking a user into triggering the request. Without additional context, the attack does not appear to require remote code execution or elevated privileges, but the ability to reach internal resources can threaten confidentiality and integrity.

Generated by OpenCVE AI on May 1, 2026 at 05:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the nK Themes Helper plugin to version 1.8.0 or newer
  • If an upgrade is not yet possible, disable the plugin so that it no longer processes external requests
  • Configure your web server or firewall to block outbound traffic from the WordPress installation to internal IP ranges and other sensitive domains until the patch is applied

Generated by OpenCVE AI on May 1, 2026 at 05:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Thu, 08 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request Forgery.This issue affects nK Themes Helper: from n/a through <= 1.7.9.
Title WordPress nK Themes Helper plugin <= 1.7.9 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:05.469Z

Reserved: 2025-01-07T21:03:44.260Z

Link: CVE-2025-22726

cve-icon Vulnrichment

Updated: 2026-01-08T14:58:29.481Z

cve-icon NVD

Status : Deferred

Published: 2026-01-08T10:15:48.247

Modified: 2026-04-27T19:16:12.380

Link: CVE-2025-22726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T06:00:13Z

Weaknesses