CVE-2023-41804 HIGH

CVE-2023-41804: WordPress Starter Templates Plugin <= 3.2.4 is vulnerable to Server Side Request Forgery (SSRF)

Vendor Brainstorm Force
Product Starter Templates — Elementor, WordPress & Beaver Builder Templates
Weakness CWE-918 · SSRF
Published December 7, 2023
Last update April 28, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N

What the vulnerability does

01Description

Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.

Explanation of Vulnerability in Simple Terms

02Summary

The Starter Templates plugin for WordPress contains a server-side request forgery (SSRF) vulnerability that allows authenticated users with low privileges to make the site send HTTP requests to internal or external systems on their behalf. An attacker can read sensitive data from internal services or interact with external APIs. The vulnerability requires network access and affects versions up to 3.2.4.

What an attacker can do

03Attacker Capabilities

Make the site send HTTP requests to internal systems or external URLs to read sensitive data or interact with services.

Potential impact on your site

04Site Impact

Attackers with basic WordPress accounts can access internal services, read metadata, or trigger actions on external systems via your site.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).

Key dates

06Disclosure timeline

December 7, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE