CVE-2026-83543
N/A
N/A
Summary
The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Greenshift | 0 < 13.2.0 | affected |
Weaknesses
- CWE-918 Server-Side Request Forgery (SSRF)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.