Impact
The vulnerability is an SSRF flaw that allows an attacker to have the server issue arbitrary requests to any URL. This can cause unauthorized data access, internal network probing, or the execution of unintended HTTP requests, potentially exposing sensitive information or further enabling malicious actions. The weakness is classified as CWE‑918.
Affected Systems
The flaw affects the WordPress Pool Services theme from any version up to and including 3.3, provided by SmartDataSoft.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk level. The EPSS score of less than 1% shows a very low likelihood of exploitation at present. Because the vulnerability is not listed in CISA KEV, there is no evidence of widespread active exploitation. Attackers would likely need to supply a URL or trigger an input that the theme processes to perform the malicious request, which is inferred but not explicitly documented in the supplied description.
OpenCVE Enrichment