Server-Side Request Forgery in EPC Photography by Unknown Vendor
CVE-2025-30964

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 April 2025

What is CVE-2025-30964?

A Server-Side Request Forgery (SSRF) vulnerability has been identified in EPC Photography. This flaw could allow attackers to manipulate server requests, potentially gaining access to sensitive information by bypassing security measures. The issue affects the EPC Photography plugin, particularly in the versions leading to 7.5.2. Proper security measures and timely updates are crucial to mitigating risks associated with this vulnerability.

Affected Version(s)

Photography 0 <= 7.7.6

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.