Impact
The reported issue is a Server‑Side Request Forgery (SSRF) in the ThemeGoods PhotoMe WordPress theme. The flaw allows an attacker to instruct the site to perform arbitrary HTTP requests to any target hostname or IP address. This can enable the attacker to probe internal network services, retrieve data from internal resources, or trigger internal actions, which is a typical consequence of SSRF. Information about remote code execution or data exfiltration is not stated in the CVE description.
Affected Systems
All WordPress sites using the ThemeGoods PhotoMe theme version 5.7.1 or earlier are affected, as the vulnerability exists in every release up to, but not including, version 5.7.2.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate risk. The EPSS score of less than 1 % suggests a low likelihood of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be web‑based: an attacker can craft a request that supplies a malicious URL, causing the theme to fetch it and the server to issue an outbound HTTP request.
OpenCVE Enrichment