CVE-2025-10137

Source
https://cve.org/CVERecord?id=CVE-2025-10137
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10137.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-10137
Published
2025-09-26T06:43:28.669Z
Modified
2026-08-12T03:51:13.528411600Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Snow Monkey <= 29.1.5 - Unauthenticated Blind Server-Side Request Forgery
Details

The Snow Monkey theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 29.1.5 via the request() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Database specific
{
    "cna_assigner": "Wordfence",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10137.json"
}
References

Affected packages

Git / github.com/inc2734/snow-monkey

Affected ranges

Type
GIT
Repo
https://github.com/inc2734/snow-monkey
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "29.1.5"
        },
        {
            "last_affected": "29.1.5"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

29.*
29.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10137.json"