VYPR

SmartAIPress

by WordPress

CVEs (1)

  • CVE-2026-16600Aug 29, 2026
    risk 0.00cvss epss

    The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary…