PT-2026-51669 · WordPress · Wp Meta Seo

·

CVE-2026-11370

·

Published

2026-06-24

·

Updated

2026-06-29

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Meta SEO versions prior to 4.5.19
Description The plugin is susceptible to Server-Side Request Forgery (SSRF), a flaw that allows an attacker to induce the server-side application to make requests to an unintended location. Authenticated users with contributor-level access or higher can exploit the new link parameter to send web requests to arbitrary locations from the application, potentially querying or modifying internal services. The HTTP response status of these requests is returned in the AJAX JSON response as status code, creating an enumeration oracle that can be used to probe internal hosts and cloud metadata services.
Recommendations Update the plugin to version 4.5.19 or later. As a temporary mitigation, restrict access to the new link parameter for users with contributor-level permissions.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11370

Affected Products

Wp Meta Seo