Server Side Request Forgery in Vehica Core by Patchstack
CVE-2026-66654

6MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 August 2026

What is CVE-2026-66654?

The Subscriber Server Side Request Forgery (SSRF) vulnerability in Vehica Core versions up to 1.0.104 allows attackers to send crafted requests to internal resources, which could lead to unauthorized access to sensitive data or services. Through this vulnerability, an attacker may exploit the server to interact with resources within a private network or leverage the server's access rights to perform malicious activities.

Affected Version(s)

Vehica Core <= 1.0.104

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Steven Julian | Patchstack Bug Bounty Program
.