Impact
A Server Side Request Forgery vulnerability exists in Pratik Ghela MakeStories (for Google Web Stories) up to and including version 3.0.4. The flaw allows an attacker who can influence input to the plugin to cause the server to make HTTP requests to arbitrary URLs. This could expose internal network addresses, retrieve sensitive information, or interact with internal services. The weakness is identified as CWE-918, and the CVSS score of 4.4 indicates a moderate risk of compromise.
Affected Systems
The affected product is the WordPress MakeStories (for Google Web Stories) plugin, developed by Pratik Ghela, from the earliest releases through version 3.0.4. All WordPress sites that have installed this plugin within that version range are potentially impacted.
Risk and Exploitability
The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. However, because the flaw can be triggered via user-controlled input, a misconfigured or compromised WordPress instance could be leveraged to perform internal network reconnaissance or access sensitive data. The moderate CVSS score reflects the removable scope of the vulnerability, but the potential for internal exposure increases the overall threat if the attacker can reach the vulnerable plugin.
OpenCVE Enrichment
EUVD