Impact
An SSRF vulnerability in the Kerfred FG Drupal to WordPress plugin allows an attacker to instruct the WordPress host to make arbitrary HTTP requests, potentially exposing internal resources or leaking sensitive data. The flaw is a classic request forging weakness identified as CWE-918, which can lead to confidentiality or integrity impact if the host is used to reach privileged internal endpoints.
Affected Systems
WordPress sites that have installed the FG Drupal to WordPress plugin version 3.90.0 or older are affected. The vulnerability applies to all releases in that range from the unknown earliest through 3.90.0, regardless of configuration.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, while an EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, further supporting a limited threat level. Exploitation would likely involve a web‑based attack that presents crafted input to the plugin’s request functionality, but no publicly documented exploit exists.
OpenCVE Enrichment
EUVD