CVE-2026-10526: EmbedPress < 4.6.1 - Unauthenticated Blind SSRF
The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind Server-Side Request Forgery).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10526?
CVE-2026-10526 has a risk rating of 62, indicating a medium level of severity.
How do I fix CVE-2026-10526?
To fix CVE-2026-10526, update the EmbedPress WordPress plugin to version 4.6.1 or later.
What type of vulnerability is CVE-2026-10526?
CVE-2026-10526 is classified as an unauthenticated blind Server-Side Request Forgery (SSRF) vulnerability.
Who can exploit CVE-2026-10526?
CVE-2026-10526 can be exploited by unauthenticated attackers due to the lack of URL validation.
What is the impact of CVE-2026-10526?
The impact of CVE-2026-10526 allows attackers to make unauthorized HTTP requests to internal hosts and services.