Server-Side Request Forgery Vulnerability in WooMS WordPress Plugin
CVE-2026-13700

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
17 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-13700?

The WooMS WordPress plugin, up to version 9.14, is susceptible to a vulnerability that allows an attacker to craft a malicious URL. This exploitation occurs due to improper validation of user-supplied URLs before executing them in server-side requests. Consequently, stored third-party integration credentials can be attached to these requests, enabling unauthorized users to execute server-side request forgery attacks. If the data-sync feature is enabled, this vulnerability poses a significant risk by potentially disclosing sensitive configuration information.

Affected Version(s)

WooMS 0 <= 9.14

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

dangnosuy
WPScan
.