Impact
The Simple Blog Card plugin for WordPress, created by Katsushi Kawamori, contains a Server‑Side Request Forgery (SSRF) flaw that permits the server to issue HTTP requests to arbitrary URLs. According to the CVE description, this weakness arises from insufficient validation of user‑supplied URLs, allowing an attacker to initiate internal network requests or exfiltrate data, thereby jeopardizing confidentiality and potentially affecting integrity of exposed services.
Affected Systems
All released versions of the Katsushi Kawamori Simple Blog Card plugin, from the earliest available version up to and including version 2.37, are affected. No higher‑numbered version has been documented as providing a fix in the supplied data.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is reported as less than 1%, suggesting a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating limited active exploitation. The provided description does not specify authentication requirements; it is inferred that the SSRF can be triggered via a publicly accessible plugin interface without special conditions, although this is not explicitly stated by the vendor.
OpenCVE Enrichment