WordPress · Wooms · CVE-2026-13700
**Name of the Vulnerable Software and Affected Versions**
WooMS versions prior to 9.15
**Description**
Insufficient validation of user-supplied URLs in the data-sync feature allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF), a technique where the server is coerced into making requests to an unintended location. During these requests, the plugin attaches stored third-party integration credentials, leading to the disclosure of sensitive configuration information.
**Recommendations**
Update WooMS to version 9.15 or later.
As a temporary mitigation, disable the data-sync feature to prevent the exploitation of the SSRF issue.