Impact
The vulnerability is a Server Side Request Forgery (SSRF) that does not require authentication; an attacker can submit crafted requests to the affected endpoint and cause the WordPress site to initiate requests to arbitrary destinations. This can expose internal network services, retrieve sensitive data from internal hosts, or provide an attack surface for further exploitation. The issue is identified as CWE‑918 and is rated with a CVSS score of 7.2, indicating a moderate to high severity.
Affected Systems
The affected product is the WordPress StreamCast plugin provided by bPlugins, with version numbers up to 2.4.5 susceptible to this flaw. Any WordPress installation running one of these versions is potentially vulnerable.
Risk and Exploitability
With a CVSS of 7.2 the vulnerability represents a serious risk; the EPSS score is not available, and it is not listed in CISA’s KEV catalog. The attack vector is inferred to be server‑side, requiring only a user‑initiated request to the vulnerable endpoint, as authentication is not needed. Because the SSRF can target arbitrary URLs, the attacker could access private IP ranges or internal resources, which could lead to data exposure or further compromise. The overall risk is moderate to high and should be addressed promptly.
OpenCVE Enrichment