SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12516

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

The Fediverse Embeds WordPress plugin prior to version 1.5.8 is vulnerable to a Server-Side Request Forgery (SSRF) due to improper validation of URLs fetched by an unauthenticated media-proxying endpoint. This flaw allows anonymous users to access arbitrary URLs, including internal and private-network addresses, potentially exposing sensitive information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-12516
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress

Original NVD Description

The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body. This results in a full-read Server-Side Request Forgery and open proxy.