CVE-2026-14939: CWE-918 Server-Side Request Forgery (SSRF) in Visualizer
The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata endpoints. As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.
AI Analysis
Technical Summary
The Visualizer WordPress plugin versions prior to 4.0.6 do not validate or restrict user-supplied URLs before fetching them server-side. This lack of validation allows authenticated users with Contributor-level permissions or above to exploit a Server-Side Request Forgery (SSRF) vulnerability. The SSRF targets link-local instance metadata endpoints commonly used in cloud environments to expose instance metadata and credentials. Because the server returns the fetched response directly, attackers can retrieve sensitive cloud instance metadata, including IAM credentials, through this vulnerability. No CVSS score or official remediation level is currently available, and no patch links have been provided.
Potential Impact
Exploitation of this vulnerability can lead to unauthorized disclosure of sensitive cloud instance metadata, including IAM credentials, on cloud-hosted sites using the vulnerable Visualizer plugin. This can result in privilege escalation and further compromise of cloud resources. The vulnerability requires at least Contributor-level access to the WordPress site, limiting exploitation to authenticated users with some level of trust. There is no indication of known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Contributor-level and higher user permissions to trusted users only. Monitor for updates from the Visualizer plugin vendor regarding patches or official mitigations.
CVE-2026-14939: CWE-918 Server-Side Request Forgery (SSRF) in Visualizer
Description
The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata endpoints. As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Visualizer WordPress plugin versions prior to 4.0.6 do not validate or restrict user-supplied URLs before fetching them server-side. This lack of validation allows authenticated users with Contributor-level permissions or above to exploit a Server-Side Request Forgery (SSRF) vulnerability. The SSRF targets link-local instance metadata endpoints commonly used in cloud environments to expose instance metadata and credentials. Because the server returns the fetched response directly, attackers can retrieve sensitive cloud instance metadata, including IAM credentials, through this vulnerability. No CVSS score or official remediation level is currently available, and no patch links have been provided.
Potential Impact
Exploitation of this vulnerability can lead to unauthorized disclosure of sensitive cloud instance metadata, including IAM credentials, on cloud-hosted sites using the vulnerable Visualizer plugin. This can result in privilege escalation and further compromise of cloud resources. The vulnerability requires at least Contributor-level access to the WordPress site, limiting exploitation to authenticated users with some level of trust. There is no indication of known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Contributor-level and higher user permissions to trusted users only. Monitor for updates from the Visualizer plugin vendor regarding patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-07T11:59:08.498Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7187cebf32cb7a34e19abd
Added to database: 08/04/2026, 06:33:50 UTC
Last enriched: 08/04/2026, 06:54:41 UTC
Last updated: 08/04/2026, 12:56:01 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.