CVE-2026-11370: WP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' Parameter
The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'newlink' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The HTTP response status from outbound requests is reflected back in the AJAX JSON response as statuscode, providing an enumeration oracle usable for probing internal hosts and cloud metadata services.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Meta SEOto a version that resolves this vulnerability.Fixed in 4.5.18 - Configuration
Fix the SSRF sink by removing/denying use of the 'new_link' parameter for outbound requests so authenticated users (Contributor+ and above) cannot cause the plugin to fetch attacker-chosen internal/external URLs.
WordPress WP Meta SEO new_link parameter = Do not allow or accept arbitrary user-supplied URLs for web requests
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11370?
The severity of CVE-2026-11370 is medium, with a score of 6.4.
What vulnerability type is CVE-2026-11370 associated with?
CVE-2026-11370 is associated with Server-Side Request Forgery (SSRF) vulnerabilities.
Who is affected by CVE-2026-11370?
CVE-2026-11370 affects authenticated users with contributor-level access and above.
How do I fix CVE-2026-11370?
To fix CVE-2026-11370, upgrade the WP Meta SEO plugin to a version later than 4.5.18.
What systems are impacted by CVE-2026-11370?
CVE-2026-11370 impacts the WP Meta SEO plugin for WordPress versions up to and including 4.5.18.