Server-Side Request Forgery in Exit Intent Popup by kamleshyadav
CVE-2025-58641

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2025

What is CVE-2025-58641?

The Exit Intent Popup plugin by kamleshyadav contains a vulnerability that allows attackers to exploit Server-Side Request Forgery (SSRF). This flaw can potentially enable unauthorized access to internal resources, posing a significant risk to users of the plugin. The vulnerability affects versions from its initial release through 1.0.1, highlighting the need for immediate attention and updates to safeguard against potential exploitation.

Affected Version(s)

Exit Intent Popup <= 1.0.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.
CVE-2025-58641 : Server-Side Request Forgery in Exit Intent Popup by kamleshyadav