The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body. This results in a full-read Server-Side Request Forgery and open proxy.
History

Tue, 04 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Sat, 01 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Sat, 25 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Tue, 21 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Thu, 16 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Wed, 15 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Mon, 13 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Mon, 13 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Thu, 09 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body. This results in a full-read Server-Side Request Forgery and open proxy.
Title Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Media Proxy
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-07-09T06:00:02.880Z

Updated: 2026-07-09T14:46:12.813Z

Reserved: 2026-06-17T12:41:37.963Z

Link: CVE-2026-12516

cve-icon Vulnrichment

Updated: 2026-07-09T14:46:08.822Z

cve-icon NVD

Status : Deferred

Published: 2026-07-09T07:16:23.303

Modified: 2026-07-09T16:34:18.103

Link: CVE-2026-12516

cve-icon Redhat

No data.