What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.
Explanation of Vulnerability in Simple Terms
02Summary
The Starter Templates plugin for WordPress contains a server-side request forgery (SSRF) vulnerability that allows authenticated users with low privileges to make the site send HTTP requests to internal or external systems on their behalf. An attacker can read sensitive data from internal services or interact with external APIs. The vulnerability requires network access and affects versions up to 3.2.4.
What an attacker can do
03Attacker Capabilities
Make the site send HTTP requests to internal systems or external URLs to read sensitive data or interact with services.
Potential impact on your site
04Site Impact
Attackers with basic WordPress accounts can access internal services, read metadata, or trigger actions on external systems via your site.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
December 7, 2023
CVE published
April 28, 2026
Record updated