Description
Server-Side Request Forgery (SSRF) vulnerability in Kerfred FG Drupal to WordPress fg-drupal-to-wp allows Server Side Request Forgery.This issue affects FG Drupal to WordPress: from n/a through <= 3.90.0.
Published: 2025-07-16
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An SSRF vulnerability in the Kerfred FG Drupal to WordPress plugin allows an attacker to instruct the WordPress host to make arbitrary HTTP requests, potentially exposing internal resources or leaking sensitive data. The flaw is a classic request forging weakness identified as CWE-918, which can lead to confidentiality or integrity impact if the host is used to reach privileged internal endpoints.

Affected Systems

WordPress sites that have installed the FG Drupal to WordPress plugin version 3.90.0 or older are affected. The vulnerability applies to all releases in that range from the unknown earliest through 3.90.0, regardless of configuration.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity, while an EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, further supporting a limited threat level. Exploitation would likely involve a web‑based attack that presents crafted input to the plugin’s request functionality, but no publicly documented exploit exists.

Generated by OpenCVE AI on April 30, 2026 at 09:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the FG Drupal to WordPress plugin to a version newer than 3.90.0.
  • Disable any plugin settings that allow outbound requests if upgrading is not immediately possible.
  • If a patch is not yet available and the plugin must remain active, completely deactivate the plugin to eliminate the SSRF vector.

Generated by OpenCVE AI on April 30, 2026 at 09:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21653 Server-Side Request Forgery (SSRF) vulnerability in Kerfred FG Drupal to WordPress allows Server Side Request Forgery. This issue affects FG Drupal to WordPress: from n/a through 3.90.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in Kerfred FG Drupal to WordPress allows Server Side Request Forgery. This issue affects FG Drupal to WordPress: from n/a through 3.90.0. Server-Side Request Forgery (SSRF) vulnerability in Kerfred FG Drupal to WordPress fg-drupal-to-wp allows Server Side Request Forgery.This issue affects FG Drupal to WordPress: from n/a through <= 3.90.0.
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Wed, 16 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00025}


Wed, 16 Jul 2025 10:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in Kerfred FG Drupal to WordPress allows Server Side Request Forgery. This issue affects FG Drupal to WordPress: from n/a through 3.90.0.
Title WordPress FG Drupal to WordPress plugin <= 3.90.0 - Server Side Request Forgery (SSRF) Vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:55.440Z

Reserved: 2025-05-19T14:13:37.939Z

Link: CVE-2025-48294

cve-icon Vulnrichment

Updated: 2025-07-16T14:31:53.044Z

cve-icon NVD

Status : Deferred

Published: 2025-07-16T11:15:25.387

Modified: 2026-04-23T15:31:03.010

Link: CVE-2025-48294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:45:25Z

Weaknesses