The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and private-network URLs and read back the parsed page metadata. This is a Server-Side Request Forgery.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Mon, 03 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Wed, 29 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Sun, 26 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Tue, 21 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Mon, 13 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Sun, 12 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Thu, 09 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and private-network URLs and read back the parsed page metadata. This is a Server-Side Request Forgery.
Title Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-09T12:51:27.261Z

Reserved: 2026-06-17T12:47:07.188Z

Link: CVE-2026-12517

cve-icon Vulnrichment

Updated: 2026-07-09T12:51:23.810Z

cve-icon NVD

Status : Deferred

Published: 2026-07-09T07:16:23.410

Modified: 2026-07-09T16:34:18.103

Link: CVE-2026-12517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:00:10Z

Weaknesses

No weakness.