
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12376 is a Server-Side Request Forgery (SSRF) vulnerability in the Icon List Block – Add Icon-Based Lists with Custom Styles WordPress plugin, developed by bPlugins. It affects all versions up to and including 1.2.1, and was published on November 18, 2025. The flaw allows authenticated attackers with Subscriber-level access or higher to make arbitrary web requests from the server via the fs_api_request function. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and resides in the fs_api_request function within the plugin's bundled bplugins_sdk library, specifically in FSActivate.php. An authenticated attacker can supply an arbitrary URL to this function, causing the WordPress server to issue HTTP requests to internal or external destinations on the attacker's behalf. The attack requires no user interaction and has low attack complexity, making it straightforward to exploit once a low-privileged account is obtained. Only valid JSON objects are reflected in the response, which limits but does not eliminate the information disclosure risk (Wordfence, WordPress Trac).
Successful exploitation allows an attacker to pivot through the WordPress server to probe and interact with internal network services that would otherwise be inaccessible from the internet, such as cloud metadata endpoints, internal APIs, or administrative interfaces. Both confidentiality and integrity are impacted at a low level — the attacker can read JSON responses from internal services and potentially trigger state-changing requests. Availability is not directly affected. The changed scope indicates the impact extends beyond the vulnerable component itself to other internal systems (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-12376. The vulnerability requires at minimum a Subscriber-level WordPress account, which limits opportunistic mass exploitation but remains a realistic threat in environments with open user registration. The EPSS score is approximately 0.025% (very low probability of exploitation in the near term). It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was assigned and disclosed by Wordfence (Wordfence).
fs_api_request function in bplugins_sdk/inc/Base/FSActivate.php.http://169.254.169.254/latest/meta-data/ for AWS metadata, or an internal service IP).fs_api_request with unusual or internal URL parameters; repeated requests from the same low-privileged user account.php-fpm, apache2) initiating unexpected outbound connections to non-standard destinations.Update the Icon List Block plugin to version 1.2.2 or later, which addresses the SSRF vulnerability. Site administrators should apply the update immediately via the WordPress dashboard (Plugins → Updates). As a temporary workaround if patching is not immediately possible, restrict user registration to prevent untrusted Subscriber-level accounts, or deactivate the plugin until the update can be applied. Network-level egress filtering on the WordPress server to block requests to internal IP ranges can reduce the impact of SSRF exploitation (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."