CVE-2025-8680 Overview
The B Slider – Gutenberg Slider Block for WP plugin for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability in versions up to and including 2.0.0. The flaw resides in the fs_api_request function, which fails to validate or restrict destination URLs before issuing outbound HTTP requests. Authenticated attackers holding subscriber-level access or higher can coerce the WordPress server into making arbitrary web requests. This allows adversaries to query and modify data on internal services that would otherwise be unreachable from the public internet. The vulnerability is tracked under CWE-918: Server-Side Request Forgery.
Critical Impact
Authenticated subscribers can pivot into internal networks, enumerate cloud metadata endpoints, and interact with services behind the WordPress host's network perimeter.
Affected Products
- B Slider – Gutenberg Slider Block for WP plugin for WordPress
- All versions less than or equal to 2.0.0
- WordPress installations exposing the plugin to subscriber-level accounts
Discovery Timeline
- 2025-08-15 - CVE-2025-8680 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8680
Vulnerability Analysis
The vulnerability originates in the fs_api_request function shipped with the B Slider plugin. The function accepts a user-supplied URL parameter and forwards it as the target of a server-side HTTP request without host allow-listing, scheme validation, or output sanitization. Because the request is issued by the WordPress backend, it inherits the network trust boundary of the hosting environment.
An authenticated attacker with subscriber privileges can direct the server to contact private RFC1918 addresses, loopback services, or cloud provider metadata endpoints such as http://169.254.169.254/. Responses may be reflected or observable through side-channel behavior, enabling reconnaissance of internal HTTP services, key-value stores, and administrative interfaces. Attackers can also issue state-changing requests against internal APIs that rely solely on network position for authorization.
Root Cause
The root cause is missing input validation on the destination URL processed by fs_api_request. The function does not enforce a fixed remote endpoint, does not verify that the target hostname resolves to a public address, and does not restrict permitted URL schemes. See the WordPress b-slider File Analysis for the pre-fix implementation.
Attack Vector
Exploitation requires network access to the WordPress site and an authenticated account at the subscriber role or above. WordPress deployments that permit open user registration are especially exposed because attackers can self-provision the required privileges. The attacker submits a crafted request to the plugin's AJAX or REST endpoint that reaches fs_api_request, supplying an internal URL as the target. The WordPress server issues the request and processes the response, giving the attacker a proxy into the internal network. Refer to the Wordfence Vulnerability Report for additional context.
Detection Methods for CVE-2025-8680
Indicators of Compromise
- Outbound HTTP requests from the WordPress host to RFC1918 addresses, loopback interfaces, or cloud metadata IPs such as 169.254.169.254
- Web server access logs showing subscriber-authenticated requests invoking B Slider endpoints with URL parameters pointing to internal hostnames
- Unexpected entries in wp-content/plugins/b-slider/ request handlers correlated with new subscriber account activity
Detection Strategies
- Inspect PHP-FPM or web server outbound connections for requests originating from the B Slider plugin's execution context targeting non-public IP ranges
- Alert on requests to fs_api_request handlers containing URL parameters with schemes other than https or hostnames resolving to internal ranges
- Correlate spikes in low-privilege user registrations with subsequent plugin AJAX calls to surface opportunistic exploitation
Monitoring Recommendations
- Enable egress filtering and log all outbound HTTP traffic from WordPress hosts for retrospective analysis
- Monitor authentication logs for anomalous subscriber account creation followed by plugin API interactions
- Instrument WordPress with request logging middleware that captures the full URL parameter passed to plugin endpoints
How to Mitigate CVE-2025-8680
Immediate Actions Required
- Update the B Slider – Gutenberg Slider Block for WP plugin to a version later than 2.0.0 as soon as a fixed release is available
- Audit WordPress user accounts and remove or downgrade unnecessary subscriber-level accounts
- Disable open user registration on sites where subscriber access is not operationally required
Patch Information
Review the WordPress b-slider Changeset for the vendor commit that addresses the SSRF condition. Administrators should confirm the installed plugin version through the WordPress admin panel and apply updates via the standard plugin update workflow.
Workarounds
- Deactivate and remove the B Slider plugin until a patched release is deployed
- Restrict outbound network access from the WordPress host using a firewall policy that blocks connections to RFC1918 ranges and cloud metadata endpoints
- Place the WordPress instance behind a web application firewall configured to inspect and block requests carrying internal URLs in plugin parameters
# Example iptables rules to block SSRF pivots to internal ranges and cloud metadata
iptables -A OUTPUT -m owner --uid-owner www-data -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 10.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 172.16.0.0/12 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 192.168.0.0/16 -j REJECT
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
