CVE-2025-10874
BaseFortify
Publication date: 2025-10-24
Last updated on: 2025-10-27
Assigner: WPScan
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wp_themes | orbit_fox | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Orbit Fox WordPress plugin before version 3.0.2. It does not restrict the URLs that can be used in its stock photo import feature, allowing an attacker to specify arbitrary URLs. This results in a server-side request forgery (SSRF), where the attacker can make the server access any URL they choose.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to make the server perform unauthorized requests to internal or external systems. This can lead to information disclosure, unauthorized access to internal services, or other malicious activities depending on what URLs the attacker forces the server to access.