What is CVE-2026-10526?
CVE-2026-10526 affects the EmbedPress WordPress plugin before version 4.6.1, where unvalidated user-supplied URLs in unauthenticated endpoints lead to a Server-Side Request Forgery (SSRF) vulnerability. Unauthenticated attackers can force the site to send HTTP requests to internal hosts and services, bypassing WordPress core URL validation. Immediate update to the latest patched version is required.
Azərbaycanca: CVE-2026-10526 EmbedPress WordPress plagini (4.6.1-dən əvvəlki versiyalarda) autentifikasiya olunmamış endpointlər vasitəsilə istifadəçi tərəfindən təqdim edilən URL-ləri düzgün yoxlamır və Server-Side Request Forgery (SSRF) zəifliyinə səbəb olur. Təcavüzkar bu yolla saytı daxili hostlara və xidmətlərə HTTP sorğuları göndərməyə məcbur edə bilər. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What type of attackers can exploit CVE-2026-10526?
This vulnerability can be exploited by unauthenticated attackers, meaning they can carry out the attack without having any account on the site.
What can an attacker achieve when the EmbedPress plugin is exploited via SSRF?
An attacker can force the site to send HTTP requests to internal hosts and services, bypassing WordPress core URL validation and potentially gaining access to internal network resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.