PT-2026-56703 · WordPress · Fediverse Embeds
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fediverse Embeds WordPress plugin versions prior to 1.5.8
Description
An unauthenticated site-info endpoint fails to validate the destination of server-side requests. This allows anonymous users to perform Server-Side Request Forgery (SSRF), a technique where an attacker induces a server-side application to make requests to an unintended location. By leveraging a gating nonce exposed on public pages, attackers can force the site to request internal and private-network URLs and retrieve the parsed page metadata.
Recommendations
Update Fediverse Embeds WordPress plugin to version 1.5.8 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fediverse Embeds