GutenKit <= 2.5.2 - Authenticated (Author+) Server-Side Request Forgery via Media Upload From URL Route
- ID
- WPSEC-2026-0555
- Plugin
- GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor (gutenkit-blocks-addon)
- Affected
- all versions before 2.5.3
- Remediation
- Update to 2.5.3 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- Weakness
- CWE-918
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- GutenKit on WPSec AttackSurface
- Fix released
- Published
Description
The GutenKit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.2 via the media upload from URL REST route, which fetched any URL supplied in the request instead of only the template library's own hosts. This makes it possible for authenticated attackers with Author-level access and above (users with the upload_files capability) to make the web server request arbitrary URLs, including on the site's own host, and save the responses as media library files they can then open, provided a response passes WordPress's upload file-type check. WordPress's safe HTTP API still blocks loopback and private-network addresses.
References
- https://wpsec.com/vuln/WPSEC-2026-0555/
- https://plugins.svn.wordpress.org/gutenkit-blocks-addon/tags/2.5.3/
- https://wordpress.org/plugins/gutenkit-blocks-addon/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS