Impact
The vulnerability allows an unauthenticated attacker to trigger the plugin to fetch arbitrary URLs, potentially accessing internal services and confidential data. This SSRF flaw can be leveraged to read internal resources, send malicious requests to internal endpoints, or pivot to further attacks, impacting confidentiality and availability of the affected WordPress environment.
Affected Systems
The flaw affects DeKnows' PDF Smart Viewer for Elementor plugin version 1.0.4 and earlier on WordPress sites. Users running those versions are at risk; newer versions beyond 1.0.4 are presumed fixed.
Risk and Exploitability
The CVSS base score of 7.2 indicates a high impact vulnerability, with no authentication required. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Attackers can exploit it from any external web client that can trigger the plugin, making it a readily exploitable SSRF risk.
OpenCVE Enrichment