Unrated severityNVD Advisory· Published Aug 17, 2026
CVE-2026-13700
CVE-2026-13700
Description
The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to disclose the configured integration credentials when the relevant data-sync feature is enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=9.14+ 1 more
- (no CPE)range: <=9.14
- (no CPE)range: <=9.14
Package: https://wordpress.org/plugins/wooms
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.