CVE-2026-3576: Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. The sendhttppost() function validates the host of the provided URL against an allowlist that includes 'localhost', but critically fails to validate the URL scheme/protocol. This makes it possible for unauthenticated attackers to supply a file:// URL (e.g., file://localhost/etc/passwd) which bypasses the host allowlist check because parseurl() returns 'localhost' as the host. The URL is then passed to curlinit() or fopen(), both of which support the file:// protocol, allowing the attacker to read arbitrary local files on the server and have their contents returned in the HTTP response. This can lead to disclosure of sensitive files such as /etc/passwd, wp-config.php (containing database credentials and authentication keys), and other server-side files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3576?
CVE-2026-3576 has a severity rating of 7.2, which is considered high.
How do I fix CVE-2026-3576?
To mitigate CVE-2026-3576, users should upgrade the Planyo Online Reservation System plugin for WordPress to version 3.1 or later.
What type of vulnerability is CVE-2026-3576?
CVE-2026-3576 is an Unauthenticated Server-Side Request Forgery vulnerability that can lead to Local File Inclusion.
Which versions of the Planyo Online Reservation System plugin are affected by CVE-2026-3576?
All versions of the Planyo Online Reservation System plugin for WordPress up to and including version 3.0 are affected by CVE-2026-3576.
What is the primary cause of CVE-2026-3576?
The primary cause of CVE-2026-3576 is insufficient input validation in the 'ulap_url' parameter of the ulap.php file.