Impact
The flaw is a Server‑Side Request Forgery (SSRF) vulnerability in the FWDesign Ultimate Video Player plugin for WordPress. It enables an attacker to command the plugin to perform arbitrary HTTP requests from the server, potentially exposing internal services or facilitating further attacks. The weakness is identified as CWE‑918 and can compromise confidentiality and integrity of data accessed through internal URLs. Based on the description, it is inferred that the attacker can target any reachable resource via the plugin’s endpoint.
Affected Systems
The vulnerability affects all versions of the FWDesign Ultimate Video Player plugin from the earliest available version up to and including 10.1. WordPress sites that have installed or upgraded to 10.1 or earlier remain susceptible.
Risk and Exploitability
The CVSS score is 7.2, indicating a high severity assessment. The EPSS score is less than 1 %, and the issue is not listed in the CISA KEV catalog, implying that exploitation is uncommon but still possible. Based on the description, it is inferred that the likely attack vector involves sending a specially crafted request to the plugin’s endpoint that triggers outbound HTTP calls to arbitrary URLs, allowing an unauthenticated attacker to probe or communicate with internal network resources if the plugin is publicly accessible.
OpenCVE Enrichment
EUVD