Impact
The vulnerability is a Server‑Side Request Forgery (SSRF) flaw in the ThemeGoods Photography WordPress theme, identified as CWE‑918. It allows an attacker to cause the site to send arbitrary HTTP requests to any destination, potentially exposing internal services or using the connection as a pivot for additional attacks. The flaw directly affects how the theme processes remote requests and does not require any other vulnerability.
Affected Systems
The affected product is the ThemeGoods Photography theme for WordPress, with every release earlier than version 7.7.6 being vulnerable. No other vendors or products are listed as impacted.
Risk and Exploitability
Based on the description, it is inferred that the attacker does not need authentication. The likely attack vector is a public‑facing request that triggers theme functionality that performs outbound HTTP calls. The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Although exploitation likelihood is low, patching is recommended to prevent potential internal exposure or further compromise.
OpenCVE Enrichment
EUVD