Impact
A server‑side request forgery flaw exists in WP ManageNinja LLC’s FluentCRM Pro plugin up to version 3.1.12. An attacker who can influence a subscriber entry can cause the plugin to issue HTTP requests to arbitrary URLs from the web server. This can lead to internal network enumeration or data exfiltration, but does not provide direct remote code execution. The weakness is identified as CWE‑918.
Affected Systems
WordPress sites running the FluentCRM Pro plugin version 3.1.12 or earlier, provided by WP ManageNinja LLC. All installations of the plugin with a version less than or equal to 3.1.12 are affected.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate impact. EPSS data is not available, so there is no published estimate of exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through crafted subscriber data that leads the plugin to fetch an attacker‑controlled address. Exploitation requires the ability to create or modify subscriber records, which may be restricted to users with sufficient permissions. The risk, while moderate, warrants timely remediation because SSRF can expose internal services if not mitigated.
OpenCVE Enrichment