Impact
The bdthemes Instant Image Generator WordPress plugin has a Server‑Side Request Forgery vulnerability that allows an attacker to supply arbitrary URLs to the image‑generation endpoint. When the server processes the request, it will perform HTTP requests to the supplied URL, potentially accessing internal resources or external services. This can lead to disclosure of confidential information, traversal inside internal networks, or denial of service if the endpoint is flooded. The weakness is classified as CWE‑918.
Affected Systems
Affected systems are WordPress installations that use the bdthemes Instant Image Generator plugin, version 2.1.4 and earlier. Administrators should verify the plugin version and disable or remove the plugin if it cannot be promptly updated.
Risk and Exploitability
The CVSS score of 6.4 categorizes this as a moderate‑severe vulnerability. The EPSS score of less than 1 % indicates that exploitation is currently unlikely, and the issue is not listed in the CISA KEV catalog. The most likely attack vector is an unauthenticated HTTP request to the plugin’s image‑generation endpoint from an external attacker. Successful exploitation would allow the attacker to make outgoing connections to arbitrary hosts from the compromised server, possibly leaking data or enabling further attacks within the internal network.
OpenCVE Enrichment