CVE-2026-27350: WordPress Builderius plugin <= 1.4-beta - Server Side Request Forgery (SSRF) vulnerability
Published Oct 10, 2026
·Updated
Server-Side Request Forgery (SSRF) vulnerability in Builderius.io Builderius allows Server Side Request Forgery.
This issue affects Builderius: from 1.4 through 1.4-beta.
Affected Software
1 affected component
Builderius Builderius<=1.4-beta
Event History
Oct 10, 2026
CVE Published
via MITRE·07:44 PM
Data Sourced
via MITRE·07:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The CVSS vector indicates the issue is exploitable over the network with low attack complexity. It requires no authentication, privileges, or user interaction.
2
What impact is indicated if exploitation succeeds?
The reported CVSS metrics indicate low confidentiality and integrity impact, with no availability impact. The scope is marked as changed, meaning effects may extend beyond the initially vulnerable component's security authority.
3
Which installations should be prioritized for review?
Prioritize Builderius installations in the reported affected range, stated as 1.4 through 1.4-beta. No information is provided about configuration-specific exposure or compensating controls.