SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-16600

HIGH · CVSS 7.7 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The SmartAIPress WordPress plugin versions up to 1.2.0 are vulnerable due to a lack of capability checks on AJAX actions and insufficient validation of user-supplied URLs. This flaw enables users with subscriber-level access and above to exploit the site by retrieving arbitrary internal or external URLs, leading to potential data exposure through Server-Side Request Forgery (SSRF). WordPress site administrators and security teams should prioritize patching this vulnerability to mitigate risks associated with unauthorized data access.

CVE
CVE-2026-16600
Severity
HIGH
CVSS
7.7
EPSS
0.20%
WordPress

Original NVD Description

The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary internal or external URLs and read the response, resulting in a full-read Server-Side Request Forgery.