Impact
This vulnerability is a Server Side Request Forgery (SSRF) flaw located in the Genemy theme bundled with WordPress. An attacker can coerce the web server into making arbitrary HTTP requests to internal or external addresses, potentially exposing sensitive data or enabling further remote exploitation. The flaw is classified as CWE-918 and carries a CVSS score of 4.9, indicating a moderate severity.
Affected Systems
WordPress installations using the Jthemes Genemy theme version 1.6.6 or earlier are affected. No later versions are known to be impacted.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely through a URL or variable that the theme processes without proper validation, allowing an attacker who can trigger the vulnerable code to make requests to arbitrary destinations from the server. The moderate CVSS rating and low EPSS suggest that while the risk is recognized, it is not currently a high‑threat target.
OpenCVE Enrichment