PT-2026-56703 · WordPress · Fediverse Embeds

·

CVE-2026-12517

·

Published

2026-07-09

·

Updated

2026-07-09

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fediverse Embeds WordPress plugin versions prior to 1.5.8
Description An unauthenticated site-info endpoint fails to validate the destination of server-side requests. This allows anonymous users to perform Server-Side Request Forgery (SSRF), a technique where an attacker induces a server-side application to make requests to an unintended location. By leveraging a gating nonce exposed on public pages, attackers can force the site to request internal and private-network URLs and retrieve the parsed page metadata.
Recommendations Update Fediverse Embeds WordPress plugin to version 1.5.8 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-12517

Affected Products

Fediverse Embeds