WordPress · Visualizer · CVE-2026-14939
**Name of the Vulnerable Software and Affected Versions**
Visualizer WordPress plugin versions prior to 4.0.6
**Description**
Users with Contributor-level access and above can perform Server-Side Request Forgery (SSRF) because the plugin fails to restrict user-supplied URLs to safe address ranges before fetching them server-side. This allows for non-blind attacks against link-local instance-metadata endpoints, enabling the retrieval of cloud instance metadata, such as IAM credentials, on cloud-hosted sites.
**Recommendations**
Update the plugin to version 4.0.6 or later.