CVE-2026-12517
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthentica
CVSS
5.3
Medio
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Publicado: 9 jul 2026 · Última mod.: 9 jul 2026
0.2%EPSS · 30 días0.3%
2026-08-142026-09-10
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and private-network URLs and read back the parsed page metadata. This is a Server-Side Request Forgery.
Sin CVEs relacionados por CWE o producto.