CVE-2025-58005: WordPress DriCub Theme <= 2.9 - Server Side Request Forgery (SSRF) Vulnerability
Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft DriCub allows Server Side Request Forgery. This issue affects DriCub: from n/a through 2.9.
Other sources
Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft DriCub dricub-driving-school allows Server Side Request Forgery.This issue affects DriCub: from n/a through <= 2.9.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58005?
CVE-2025-58005 is classified as a critical Server-Side Request Forgery (SSRF) vulnerability.
How do I fix CVE-2025-58005?
To fix CVE-2025-58005, upgrade SmartDataSoft DriCub to version 2.10 or later.
What systems are affected by CVE-2025-58005?
CVE-2025-58005 affects SmartDataSoft DriCub versions up to and including 2.9 and WordPress DriCub Theme versions up to and including 2.9.
Can CVE-2025-58005 be exploited remotely?
Yes, CVE-2025-58005 can be exploited remotely through crafted requests.
What are the potential consequences of CVE-2025-58005?
Exploitation of CVE-2025-58005 may allow attackers to make unauthorized requests to internal resources, leading to data exposure or further attacks.