CVE · High

CVE-2023-41804 — Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 3.2.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-41804 Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 3.2.5 Server-Side Request Forgery (SSRF) High 7.1 < 3.2.5 3.2.5 2023-09-05

CVE-2023-41804

The Starter Templates plugin for WordPress contained a server-side request forgery flaw in versions before 3.2.5 that could enable attackers to manipulate a compromised website into making requests to arbitrary attacker-controlled domains. This vulnerability potentially exposed sensitive data from internal services or other systems accessible from the affected server. The issue was identified by Rafie Muhammad from Patchstack and has been resolved in version 3.2.5 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.