Server-Side Request Forgery in Exit Intent Popup by kamleshyadav
CVE-2025-58641
5.4MEDIUM
What is CVE-2025-58641?
The Exit Intent Popup plugin by kamleshyadav contains a vulnerability that allows attackers to exploit Server-Side Request Forgery (SSRF). This flaw can potentially enable unauthorized access to internal resources, posing a significant risk to users of the plugin. The vulnerability affects versions from its initial release through 1.0.1, highlighting the need for immediate attention and updates to safeguard against potential exploitation.
Affected Version(s)
Exit Intent Popup <= 1.0.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)