Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 06 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jegstudio
Jegstudio gutenverse – Ultimate Wordpress Fse Blocks Addons & Ecosystem Wordpress Wordpress wordpress |
|
| Vendors & Products |
Jegstudio
Jegstudio gutenverse – Ultimate Wordpress Fse Blocks Addons & Ecosystem Wordpress Wordpress wordpress |
Tue, 05 May 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.5.3 via the import_images() function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. | |
| Title | Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor+) Server-Side Request Forgery via 'imageUrl' | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-06T14:04:31.871Z
Reserved: 2026-02-21T18:56:55.447Z
Link: CVE-2026-2948
Updated: 2026-05-06T14:04:27.870Z
Status : Deferred
Published: 2026-05-05T04:16:09.120
Modified: 2026-05-05T19:08:20.090
Link: CVE-2026-2948
No data.
OpenCVE Enrichment
Updated: 2026-05-05T05:30:16Z