VYPR

Content Syndication Toolkit

by WordPress

CVEs (1)

  • CVE-2026-3478HigMar 21, 2026
    risk 0.47cvss 7.2epss 0.00

    The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3 via the redux_p AJAX action in the bundled ReduxFramework library. The plugin registers a proxy endpoint (wp_ajax_nopriv_redux_p) that is…