Vulnerabilities / GutenKit / WPSEC-2026-0555

GutenKit <= 2.5.2 - Authenticated (Author+) Server-Side Request Forgery via Media Upload From URL Route

Medium 5.0 CWE-918Fixed in 2.5.3
ID
WPSEC-2026-0555
Plugin
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor (gutenkit-blocks-addon)
Affected
all versions before 2.5.3
Remediation
Update to 2.5.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Weakness
CWE-918
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
GutenKit on WPSec AttackSurface
Fix released
Published

Description

The GutenKit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.2 via the media upload from URL REST route, which fetched any URL supplied in the request instead of only the template library's own hosts. This makes it possible for authenticated attackers with Author-level access and above (users with the upload_files capability) to make the web server request arbitrary URLs, including on the site's own host, and save the responses as media library files they can then open, provided a response passes WordPress's upload file-type check. WordPress's safe HTTP API still blocks loopback and private-network addresses.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0