First published: Fri Jan 24 2025(Updated: )
Server-Side Request Forgery (SSRF) vulnerability in HasThemes Extensions For CF7 allows Server Side Request Forgery. This issue affects Extensions For CF7: from n/a through 3.2.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
HasThemes Extensions For CF7 | <=3.2.0 | |
WordPress Extensions For CF7 Plugin | <=3.2.0 |
Update the WordPress Extensions For CF7 wordpress plugin to the latest available version (at least 3.2.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24695 is classified as a high severity Server-Side Request Forgery (SSRF) vulnerability.
To fix CVE-2025-24695, update HasThemes Extensions For CF7 to version 3.2.1 or later.
CVE-2025-24695 affects HasThemes Extensions For CF7 versions up to and including 3.2.0.
A Server-Side Request Forgery (SSRF) vulnerability allows an attacker to send crafted requests from the server, potentially leading to unauthorized access to internal systems.
Yes, CVE-2025-24695 can be exploited remotely if an attacker is able to send requests that leverage the SSRF vulnerability.