SB2026091002 - Server-Side Request Forgery (SSRF) in WPGraphQL



SB2026091002 - Server-Side Request Forgery (SSRF) in WPGraphQL

Published: September 10, 2026

Security Bulletin ID SB2026091002
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N]


The vulnerability allows a remote user to access internal services and disclose sensitive information.

The vulnerability exists due to an incomplete list of disallowed inputs in the createMediaItem GraphQL mutation when processing filePath URLs that use DNS hostnames resolving to link-local addresses. A remote user can submit a crafted filePath URL using a DNS hostname that resolves to a link-local address to access internal services and disclose sensitive information.

On cloud hosts exposing IMDSv1, temporary cloud credentials may be exposed through the Media Library.


Remediation

Install update from vendor's website.