A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.26
EPSS Ranking 96.0%