Server-Side Request Forgery Vulnerability in WooMS WordPress Plugin
CVE-2026-13700
Key Information:
Badges
What is CVE-2026-13700?
The WooMS WordPress plugin, up to version 9.14, is susceptible to a vulnerability that allows an attacker to craft a malicious URL. This exploitation occurs due to improper validation of user-supplied URLs before executing them in server-side requests. Consequently, stored third-party integration credentials can be attached to these requests, enabling unauthorized users to execute server-side request forgery attacks. If the data-sync feature is enabled, this vulnerability poses a significant risk by potentially disclosing sensitive configuration information.
Affected Version(s)
WooMS 0 <= 9.14
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.