๐Ÿ” CVE Alert

CVE-2025-49983

UNKNOWN 0.0

WordPress WPThumb plugin <= 0.10 - Server Side Request Forgery (SSRF) Vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Server-Side Request Forgery (SSRF) vulnerability in Joe Hoyle WPThumb wp-thumb allows Server Side Request Forgery.This issue affects WPThumb: from n/a through <= 0.10.

CWE CWE-918
Vendor joe hoyle
Product wpthumb
Published Jun 20, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for joe hoyle wpthumb

Be the first to know when new unknown vulnerabilities affecting joe hoyle wpthumb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Joe Hoyle / WPThumb
0 โ‰ค 0.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/wp-thumb/vulnerability/wordpress-wpthumb-plugin-0-10-server-side-request-forgery-ssrf-vulnerability?_s_id=cve

Credits

Nguyen Tran Tuan Dung (domiee13) | Patchstack Bug Bounty Program