The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Server-Side Request Forgery in version less than, or equal to, 2.0.0 via the fs_api_request function. This makes it possible for authenticated attackers, with subscriber-level access and above to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Aug 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 15 Aug 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bplugins
Bplugins b Slider Wordpress Wordpress wordpress |
|
Vendors & Products |
Bplugins
Bplugins b Slider Wordpress Wordpress wordpress |
Fri, 15 Aug 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Server-Side Request Forgery in version less than, or equal to, 2.0.0 via the fs_api_request function. This makes it possible for authenticated attackers, with subscriber-level access and above to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services. | |
Title | B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Server-Side Request Forgery | |
Weaknesses | CWE-918 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-08-15T02:24:23.123Z
Updated: 2025-08-15T12:43:33.637Z
Reserved: 2025-08-06T18:49:06.064Z
Link: CVE-2025-8680

Updated: 2025-08-15T12:43:30.520Z

Status : Awaiting Analysis
Published: 2025-08-15T03:15:37.260
Modified: 2025-08-15T13:12:51.217
Link: CVE-2025-8680

No data.