CVE-2026-66654: WordPress Vehica Core plugin <= 1.0.104 - Server Side Request Forgery (SSRF) vulnerability
Published Aug 13, 2026
·Updated
Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.
Affected Software
1 affected component
WordPress Vehica Core Plugin<=1.0.104
Event History
Aug 13, 2026
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66654?
The severity of CVE-2026-66654 is medium with a score of 6.
2
How do I fix CVE-2026-66654?
To fix CVE-2026-66654, update the WordPress Vehica Core plugin to version 1.0.105 or later.
3
What type of vulnerability is CVE-2026-66654?
CVE-2026-66654 is a Server Side Request Forgery (SSRF) vulnerability.
4
Who is affected by CVE-2026-66654?
CVE-2026-66654 affects users of the WordPress Vehica Core plugin version 1.0.104 and below.
5
When was CVE-2026-66654 published?
CVE-2026-66654 was published on August 13, 2026.