Server-Side Request Forgery Vulnerability in Solace Extra by SolaceWP
CVE-2025-58203

4.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 August 2025

What is CVE-2025-58203?

The Solace Extra plugin by SolaceWP is vulnerable to Server-Side Request Forgery (SSRF), allowing malicious users to exploit the functionality to send unauthorized requests from the server to internal or external resources. This issue compromises the integrity of the system configuration and can lead to further exposure of sensitive data within the affected environment. Users of Solace Extra versions n/a through 1.3.2 are advised to apply necessary security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Solace Extra <= 1.3.2

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Que Thanh Tuan - Blue Rock (Patchstack Alliance)
.
CVE-2025-58203 : Server-Side Request Forgery Vulnerability in Solace Extra by SolaceWP