SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-13700

MEDIUM · CVSS 5.9 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

The WooMS WordPress plugin versions up to 9.14 are vulnerable due to improper validation of user-supplied URLs, which can lead to Server-Side Request Forgery (SSRF) attacks. This flaw allows unauthenticated attackers to exploit the vulnerability and potentially disclose sensitive third-party integration credentials when the data-sync feature is active. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of credential exposure and unauthorized access.

CVE
CVE-2026-13700
Severity
MEDIUM
CVSS
5.9
EPSS
0.27%
WordPress

Original NVD Description

The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to disclose the configured integration credentials when the relevant data-sync feature is enabled.