The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
CVE ID: CVE-2023-1895
CVSS Base Severity: HIGH
CVSS Base Score: 8.5
Vendor: jetmonsters
Product: Getwid – Gutenberg Blocks
EPSS Score: 0.08% (probability of being exploited)
EPSS Percentile: 37.21% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)