Skip to main content
Vulnerability Database/CVE-2025-58977

CVE-2025-58977: WP eBay Product Feeds SSRF Vulnerability

CVE-2025-58977 is a server-side request forgery vulnerability in WP eBay Product Feeds plugin that enables attackers to make unauthorized server requests. This post covers technical details, affected versions through 3.4.8, and mitigation.

Published:

CVE-2025-58977 Overview

CVE-2025-58977 is a Server-Side Request Forgery (SSRF) vulnerability in the Rhys Wynne WP eBay Product Feeds plugin (ebay-feeds-for-wordpress) for WordPress. The flaw affects all versions up to and including 3.4.8 and allows an authenticated attacker with low privileges to coerce the WordPress server into issuing arbitrary HTTP requests. The vulnerability is tracked under CWE-918: Server-Side Request Forgery and was reported through Patchstack.

Critical Impact

An authenticated attacker can use the vulnerable plugin to pivot requests through the WordPress host, reaching internal network services, cloud metadata endpoints, or other resources normally unreachable from the public internet.

Affected Products

  • WP eBay Product Feeds (ebay-feeds-for-wordpress) WordPress plugin
  • All versions from unspecified initial release through 3.4.8
  • WordPress sites running the plugin with authenticated low-privilege users

Discovery Timeline

  • 2025-09-09 - CVE-2025-58977 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-58977

Vulnerability Analysis

The vulnerability allows an authenticated attacker with low privileges to trigger outbound HTTP requests from the WordPress server to arbitrary URLs. The attack requires network access and user interaction is not needed, but the attack complexity is rated high, suggesting non-trivial conditions must be met for successful exploitation. The scope is changed, meaning the vulnerability impacts resources beyond the vulnerable component itself.

According to Patchstack, the issue stems from the plugin accepting user-controlled URL input and passing it to a server-side HTTP client without validating the destination. This enables an attacker to probe internal infrastructure, read responses from loopback services, or interact with cloud instance metadata services such as AWS IMDS.

Root Cause

The root cause is insufficient validation of user-supplied URLs before the plugin issues server-side HTTP requests. The plugin does not restrict destinations to the expected eBay API endpoints and does not block requests to private IP ranges, loopback addresses, or link-local metadata endpoints. This matches the pattern described in CWE-918.

Attack Vector

An authenticated attacker submits a crafted URL to a plugin feature that fetches remote content. The WordPress server resolves the URL and issues an HTTP request from its own network position. Response data or side effects may be returned to the attacker, enabling reconnaissance of internal services, exfiltration of metadata credentials in cloud environments, or interaction with unauthenticated internal APIs. Full technical details are documented in the Patchstack SSRF Vulnerability Report.

Detection Methods for CVE-2025-58977

Indicators of Compromise

  • Outbound HTTP requests from the WordPress host targeting internal IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or loopback (127.0.0.1).
  • Requests from the WordPress PHP process to cloud metadata endpoints such as 169.254.169.254.
  • Unexpected wp-admin POST requests to plugin endpoints associated with ebay-feeds-for-wordpress from low-privilege accounts.

Detection Strategies

  • Inspect web server and PHP access logs for plugin requests containing URL parameters pointing to non-eBay domains or private address space.
  • Correlate authenticated session activity with outbound HTTP egress from the WordPress host using network flow logs.
  • Audit installed WordPress plugins for ebay-feeds-for-wordpress version 3.4.8 or earlier.

Monitoring Recommendations

  • Enable egress filtering logs on hosts running WordPress and alert on connections to RFC1918 and link-local destinations.
  • Monitor cloud workload metadata access and alert on IMDS requests originating from web application processes.
  • Track creation and privilege changes for WordPress accounts to limit the pool of users who can trigger plugin functionality.

How to Mitigate CVE-2025-58977

Immediate Actions Required

  • Identify all WordPress sites running the WP eBay Product Feeds plugin and confirm the installed version.
  • Deactivate and remove the plugin on any site running version 3.4.8 or earlier until a patched release is confirmed.
  • Rotate any cloud instance credentials that may have been exposed through the WordPress host's metadata endpoint.

Patch Information

At the time of the NVD entry, no fixed version is documented. Review the Patchstack SSRF Vulnerability Report for the latest patch status and upgrade to a release higher than 3.4.8 once published by the vendor.

Workarounds

  • Remove or disable the ebay-feeds-for-wordpress plugin until a fixed version is available.
  • Enforce egress filtering on the WordPress host to block outbound requests to internal IP ranges and 169.254.169.254.
  • On AWS workloads, require IMDSv2 to prevent SSRF-based retrieval of instance credentials.
  • Restrict plugin-accessible roles to trusted administrators and remove unnecessary low-privilege accounts.
bash
# Example: block egress to cloud metadata and private ranges from the web server
iptables -A OUTPUT -m owner --uid-owner www-data -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 10.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 172.16.0.0/12 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 192.168.0.0/16 -j REJECT

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.