SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-83543

MEDIUM · CVSS 4.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Greenshift WordPress plugin prior to version 13.2.0 is vulnerable due to inadequate validation of user-supplied URLs, enabling users with contributor-level access and higher to make server-side requests to arbitrary hosts and potentially read sensitive responses. This flaw poses a risk of information disclosure and could be exploited for further attacks. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-83543
Severity
MEDIUM
CVSS
4.1
EPSS
0.18%
WordPress

Original NVD Description

The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.