PT-2026-36962 · WordPress · Gutenverse

Published

2026-05-05

·

Updated

2026-05-05

·

CVE-2026-2948

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem versions prior to 3.5.4
Description An issue exists where authenticated attackers with contributor-level access and above can perform Server-Side Request Forgery (SSRF), which is a flaw allowing a server to be coerced into making requests to an unintended location. This is possible through the import images() function, enabling attackers to make web requests to arbitrary locations from the web application to query or modify information from internal services.
Recommendations Update to a version later than 3.5.3. As a temporary workaround, restrict access to the import images() function to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2948

Affected Products

Gutenverse