Impact
Unauthenticated Server Side Request Forgery (SSRF) is present in all Gutenverse Companion plugin releases up to version 2.5.1. An attacker can manipulate the plugin to instruct the WordPress site to retrieve arbitrary URLs, which can lead to remote information disclosure, internal network reconnaissance, or exploitation of other vulnerable systems accessed from the host. The vulnerability stems from insufficient validation of URLs passed through the plugin and is classified as CWE-918.
Affected Systems
This issue affects WordPress installations that use the Jegstudio Gutenverse Companion plugin version 2.5.1 or earlier. All sites running these versions are susceptible; those with newer releases are not affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity level. The EPSS score is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known, widespread exploitation as of now. Because the SSRF is unauthenticated, an attacker merely needs to send a crafted request to the vulnerable website; no special credentials or elevated privileges are required. The risk remains high until the plugin is updated to a non‑vulnerable version.
OpenCVE Enrichment