CVE-2026-10526: CWE-918 Server-Side Request Forgery (SSRF) in EmbedPress
The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind Server-Side Request Forgery).
AI Analysis
Technical Summary
The EmbedPress WordPress plugin prior to version 4.6.1 fails to validate user-supplied URLs before making server-side HTTP requests through unauthenticated endpoints. This allows unauthenticated attackers to induce the server to send requests to internal network hosts and services that are not covered by WordPress core URL validation. The vulnerability is classified as CWE-918 (Server-Side Request Forgery). No CVSS score or detailed vendor advisory is available, and no patch or remediation level has been confirmed.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to cause the affected server to make HTTP requests to internal systems or services that are otherwise inaccessible externally. This can potentially lead to information disclosure or further internal network reconnaissance. However, no known exploits in the wild have been reported, and the exact impact depends on the internal network configuration and services accessible via SSRF.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to unauthenticated endpoints if possible and monitor for unusual outbound HTTP requests from the server. Avoid exposing the vulnerable plugin version in production environments.
CVE-2026-10526: CWE-918 Server-Side Request Forgery (SSRF) in EmbedPress
Description
The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind Server-Side Request Forgery).
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The EmbedPress WordPress plugin prior to version 4.6.1 fails to validate user-supplied URLs before making server-side HTTP requests through unauthenticated endpoints. This allows unauthenticated attackers to induce the server to send requests to internal network hosts and services that are not covered by WordPress core URL validation. The vulnerability is classified as CWE-918 (Server-Side Request Forgery). No CVSS score or detailed vendor advisory is available, and no patch or remediation level has been confirmed.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to cause the affected server to make HTTP requests to internal systems or services that are otherwise inaccessible externally. This can potentially lead to information disclosure or further internal network reconnaissance. However, no known exploits in the wild have been reported, and the exact impact depends on the internal network configuration and services accessible via SSRF.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to unauthenticated endpoints if possible and monitor for unusual outbound HTTP requests from the server. Avoid exposing the vulnerable plugin version in production environments.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-06-01T09:15:56.344Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7187cebf32cb7a34e19aa8
Added to database: 08/04/2026, 06:33:50 UTC
Last enriched: 08/04/2026, 07:09:48 UTC
Last updated: 08/04/2026, 12:56:01 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.