VYPR

Wordpress Webmention

by WordPress

Source repositories

CVEs (2)

  • CVE-2026-0686HigApr 2, 2026
    risk 0.40cvss 7.2epss 0.00

    The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 in the 'MF2::parse_authorpage' function via the 'Receiver::post' function. This makes it possible for unauthenticated attackers to make web requests to…

  • CVE-2026-0688MedApr 2, 2026
    risk 0.35cvss 6.4epss 0.00

    The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 via the 'Tools::read' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to…