Impact
The Greenshift WordPress plugin allows a contributor or higher‑privileged user to submit a URL that the server will retrieve without validation, causing the server to make arbitrary HTTP requests and return the response. This flaw makes the site vulnerable to server side request forgery, potentially enabling attackers to access internal resources, exfiltrate data, or pivot to other systems if the server can reach privileged hosts.
Affected Systems
The vulnerability exists in all versions of the Greenshift plugin released before 13.2.0. Users running any of those versions, especially with contributor‑level or higher roles in WordPress, are at risk. Upgrading to 13.2.0 or later removes the unvalidated fetch capability.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity, while the EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers with contributor‑level access would target the get‑csv‑to‑json REST endpoint to supply a crafted URL, causing the server to fetch arbitrary resources and expose internal or external content to the attacker.
OpenCVE Enrichment