Critical severity9.8NVD Advisory· Published Apr 20, 2021· Updated Jun 17, 2026
CVE-2020-35313
CVE-2020-35313
Description
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- WonderCMS/WonderCMSdescription
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/160310/WonderCMS-3.1.3-Code-Execution-Server-Side-Request-Forgery.htmlnvdExploitThird Party AdvisoryVDB Entry
- zetc0de.github.io/post/authenticated-rce-ssrf-wondercms/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.