Server-Side Request Forgery (SSRF) in WordPress - #VU141186
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to send requests to unintended network locations.
The vulnerability exists due to server-side request forgery in URL validation when processing user-supplied URLs. A remote attacker can supply a crafted URL to send requests to unintended network locations.
The issue allows requests to link-local ranges.