CVE-2026-10526: The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated at
The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind Server-Side Request Forgery).
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-10526
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-10526 | coverage & exploitation status | NVD · CVE.org |
More from NVD Recent CVEs
- highCVE-2026-67243: freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerab…2026-08-04
- unknownCVE-2026-18759: The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based i…2026-08-04
- highCVE-2026-18755: A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write acc…2026-08-04
- criticalCVE-2026-18754: The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web…2026-08-04
- criticalCVE-2026-18753: The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web…2026-08-04