Server-Side Request Forgery in WP CTA Plugin by WordPress
CVE-2026-6089
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2026
What is CVE-2026-6089?
The WP CTA plugin in WordPress presents a significant security risk due to a Server-Side Request Forgery vulnerability. This flaw arises from the handling of the 'sticky_s_media' parameter in JSON file imports. The import_sidebars() function inadequately validates user-supplied URLs, allowing authenticated attackers with Administrator-level access to issue web requests to internal services. This access can lead to potentially sensitive internal data being queried and modified, as the response content is stored as a WordPress media attachment, exacerbating the severity of the exposure.
Affected Version(s)
WP CTA β Call Now Button, Sticky Button & Call to Action Builder 2.1.2