WordPress Plugin Vulnerabilities

Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint

Description

The plugin does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and private-network URLs and read back the parsed page metadata. This is a Server-Side Request Forgery.

Proof of Concept

Affects Plugins

Fixed in 1.5.8

References

Classification

Type
SSRF
OWASP top 10
CWE

Miscellaneous

Original Researcher
0xBassia
Submitter
0xBassia
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-06-18 (about 4 days ago)
Added
2026-06-18 (about 3 days ago)
Last Updated
2026-06-18 (about 3 days ago)

Other