PT-2026-56702 · WordPress · Fediverse Embeds
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fediverse Embeds WordPress plugin versions prior to 1.5.8
Description
An unauthenticated media-proxying endpoint fails to validate the destination of server-side requests. This allows anonymous users to force the site to fetch arbitrary URLs, including internal and private-network addresses, and read the response body. This issue leads to a full-read Server-Side Request Forgery (SSRF), where the server is coerced into making requests to an unintended location, and creates an open proxy.
Recommendations
Update Fediverse Embeds WordPress plugin to version 1.5.8 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fediverse Embeds