Server-Side Request Forgery Vulnerability in Publitio by Publitio
CVE-2025-58962

6.4MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
22 September 2025

What is CVE-2025-58962?

A Server-Side Request Forgery (SSRF) vulnerability exists in Publitio, which could allow an attacker to manipulate the server to make requests to unintended locations. This flaw affects all versions of Publitio up to and including 2.2.1, enabling potential exploitation that could compromise sensitive data and backend services. It is crucial for users of Publitio to assess their exposure and implement necessary safeguards to mitigate the risk associated with this vulnerability.

Affected Version(s)

Publitio <= 2.2.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ (Patchstack Alliance)
.
CVE-2025-58962 : Server-Side Request Forgery Vulnerability in Publitio by Publitio