Description
Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Electrician - Electrical Service WordPress electrician allows Server Side Request Forgery.This issue affects Electrician - Electrical Service WordPress: from n/a through <= 5.6.
Published: 2026-01-22
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server Side Request Forgery (SSRF) vulnerability
Action: Apply Patch
AI Analysis

Impact

A Server Side Request Forgery flaw exists in the Electrician - Electrical Service WordPress theme via SmartDataSoft. The vulnerability originates from an improperly validated server‑side request that allows an attacker to instruct the site to fetch arbitrary URLs. The associated weakness is CWE‑918. If exploited, an attacker could cause the site to contact internal or external endpoints, potentially leaking sensitive data, triggering internal processes, or accessing resources not intended for public use. The impact includes compromising confidentiality, integrity, or availability of internal services accessed through the theme’s request handling.

Affected Systems

SmartDataSoft’s Electrician - Electrical Service WordPress theme is affected for all releases up to and including version 5.6. Systems deploying this theme with any major or minor version equal to or less than 5.6 are potentially vulnerable. The issue does not specifically list newer versions, so all those previous releases remain at risk.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is less than 1%, denoting a very low likelihood of exploitation at the time of this analysis. The vulnerability is not currently cataloged in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is a remote, publicly accessible request that triggers the theme’s server‑side request capability. While the description does not detail authentication requirements or network isolation, SSRF flaws typically exploit remote code execution paths that are reachable over the web.

Generated by OpenCVE AI on April 16, 2026 at 07:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Electrician theme to a version that addresses the SSRF flaw (for example, any release newer than 5.6, if available).
  • Disable or remove any theme functions that perform remote HTTP requests via WordPress’s HTTP API, or restrict the allowed URLs those functions can target.
  • If an upgrade is not immediately possible, consider deactivating the theme or switching to a different, vetted WordPress theme to eliminate the vulnerable code.
  • Deploy a web application firewall or security plugin configured to block unexpected outbound requests from the WordPress installation, limiting exposure to the SSRF vector.

Generated by OpenCVE AI on April 16, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 27 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Smartdatasoft
Smartdatasoft electrician - Electrical Service Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Smartdatasoft
Smartdatasoft electrician - Electrical Service Wordpress
Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Electrician - Electrical Service WordPress electrician allows Server Side Request Forgery.This issue affects Electrician - Electrical Service WordPress: from n/a through <= 5.6.
Title WordPress Electrician - Electrical Service WordPress theme <= 5.6 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References

Subscriptions

Smartdatasoft Electrician - Electrical Service Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:13:36.792Z

Reserved: 2026-01-07T12:21:24.564Z

Link: CVE-2026-22358

cve-icon Vulnrichment

Updated: 2026-01-27T18:42:33.532Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:31.850

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-22358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T08:00:11Z

Weaknesses