Description
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
Published: 2026-08-13
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Server Side Request Forgery (SSRF) is present in all Gutenverse Companion plugin releases up to version 2.5.1. An attacker can manipulate the plugin to instruct the WordPress site to retrieve arbitrary URLs, which can lead to remote information disclosure, internal network reconnaissance, or exploitation of other vulnerable systems accessed from the host. The vulnerability stems from insufficient validation of URLs passed through the plugin and is classified as CWE-918.

Affected Systems

This issue affects WordPress installations that use the Jegstudio Gutenverse Companion plugin version 2.5.1 or earlier. All sites running these versions are susceptible; those with newer releases are not affected.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity level. The EPSS score is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known, widespread exploitation as of now. Because the SSRF is unauthenticated, an attacker merely needs to send a crafted request to the vulnerable website; no special credentials or elevated privileges are required. The risk remains high until the plugin is updated to a non‑vulnerable version.

Generated by OpenCVE AI on August 13, 2026 at 16:08 UTC.

Remediation

Vendor Solution

Update the WordPress Gutenverse Companion Plugin to the latest available version (at least 2.5.2).


OpenCVE Recommended Actions

  • Update the Gutenverse Companion plugin to version 2.5.2 or later to eliminate the SSRF flaw.
  • If an immediate upgrade is not possible, consider disabling the Gutenverse Companion plugin until a patch is applied, or uninstall it if it is unnecessary for your site.
  • Restrict the WordPress site's outbound HTTP/HTTPS traffic using firewall rules to limit connections to approved external domains or IP ranges, thereby reducing the potential impact of any SSRF attempt.

Generated by OpenCVE AI on August 13, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
Title WordPress Gutenverse Companion plugin <= 2.5.1 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:47:16.363Z

Reserved: 2026-07-27T14:01:16.156Z

Link: CVE-2026-66704

cve-icon Vulnrichment

Updated: 2026-08-13T14:29:57.543Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:11.043

Modified: 2026-08-13T16:18:47.403

Link: CVE-2026-66704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:15:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)