# GutenKit <= 2.5.2 - Authenticated (Author+) Server-Side Request Forgery via Media Upload From URL Route

- **ID:** WPSEC-2026-0555
- **Plugin:** GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor (`gutenkit-blocks-addon`), https://wordpress.org/plugins/gutenkit-blocks-addon/
- **Affected versions:** all versions before 2.5.3
- **Fixed in:** 2.5.3 (Update to 2.5.3 or later.)
- **Severity:** Medium 5.0 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N)
- **Weakness:** CWE-918
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/gutenkit-blocks-addon
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0555/

## Description

The GutenKit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.2 via the media upload from URL REST route, which fetched any URL supplied in the request instead of only the template library's own hosts. This makes it possible for authenticated attackers with Author-level access and above (users with the upload_files capability) to make the web server request arbitrary URLs, including on the site's own host, and save the responses as media library files they can then open, provided a response passes WordPress's upload file-type check. WordPress's safe HTTP API still blocks loopback and private-network addresses.

## References

- https://wpsec.com/vuln/WPSEC-2026-0555/
- https://plugins.svn.wordpress.org/gutenkit-blocks-addon/tags/2.5.3/
- https://wordpress.org/plugins/gutenkit-blocks-addon/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0555/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
