SB2026091002 - Server-Side Request Forgery (SSRF) in WPGraphQL
Published: September 10, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N]
The vulnerability allows a remote user to access internal services and disclose sensitive information.
The vulnerability exists due to an incomplete list of disallowed inputs in the createMediaItem GraphQL mutation when processing filePath URLs that use DNS hostnames resolving to link-local addresses. A remote user can submit a crafted filePath URL using a DNS hostname that resolves to a link-local address to access internal services and disclose sensitive information.
On cloud hosts exposing IMDSv1, temporary cloud credentials may be exposed through the Media Library.
Remediation
Install update from vendor's website.