CVE-2026-32467: WordPress [Aotuman] Grab WeChat Articles plugin <= 2.0.1 - Server Side Request Forgery (SSRF) vulnerability
Published Aug 18, 2026
·Updated
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
Affected Software
1 affected component
WordPress/Aotuman Grab WeChat Articles<=2.0.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress [Aotuman] Grab WeChat Articlesto a version that resolves this vulnerability.Fixed in 2.0.1
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Sites using the affected plugin through version 2.0.1 are in scope. Exploitation requires an attacker to have Subscriber-level access.
2
What are the exploitation conditions and reported impact?
The attack is network-reachable, requires no user interaction, and has high attack complexity. The reported impacts are low confidentiality, integrity, and availability effects, with scope changed.