CVE-2026-0686

Source
https://cve.org/CVERecord?id=CVE-2026-0686
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0686.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-0686
Published
2026-04-02T07:39:35.655Z
Modified
2026-08-12T03:51:34.305537829Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Webmention <= 5.6.2 - Unauthenticated Blind Server-Side Request Forgery
Details

The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 in the 'MF2::parse_authorpage' function via the 'Receiver::post' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Database specific
{
    "cwe_ids": [
        "CWE-918"
    ],
    "cna_assigner": "Wordfence",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0686.json"
}
References

Affected packages

Git / github.com/pfefferle/wordpress-webmention

Affected ranges

Type
GIT
Repo
https://github.com/pfefferle/wordpress-webmention
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "5.6.2"
        }
    ]
}

Affected versions

2.*
2.4.0
2.5.0
2.6.0
3.*
3.0.0
3.0.0-beta1
3.0.1
3.1.0
3.1.1
3.2.1
3.3.0
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.8.10
3.8.11
3.8.2
3.8.4
3.8.5
3.8.6
3.8.7
3.8.8
3.8.9
4.*
4.0.0
4.0.1
4.0.2
4.0.3
5.*
5.0.0
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.5.0
5.6.0
5.6.1
5.6.2
Other
mf2-version

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0686.json"