Server-Side Request Forgery Vulnerability in Webmention Plugin for WordPress
CVE-2026-0686
7.2HIGH
What is CVE-2026-0686?
The Webmention plugin for WordPress is susceptible to a Server-Side Request Forgery vulnerability affecting all versions up to 5.6.2. This issue resides in the 'MF2::parse_authorpage' function and can be exploited through the 'Receiver::post' function. Unauthenticated attackers can leverage this vulnerability to send web requests to arbitrary locations from the web application, enabling them to potentially query and manipulate information from internal services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Webmention 0 <= 5.6.2