WordPress Vulnerabilities
WP < 7.0.3 - Unauthenticated Blind SSRF
Description
WordPress does not block requests to all reserved and internal IP address ranges, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services (a blind Server-Side Request Forgery).
Affects WordPress
References
Classification
Type
SSRF
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Andrew MacPherson
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-06 (about 1 month ago)
Added
2026-08-06 (about 1 month ago)
Last Updated
2026-08-06 (about 1 month ago)