What is CVE-2026-13700?
CVE-2026-13700 is a critical Server-Side Request Forgery (SSRF) vulnerability in the WooMS WordPress plugin through version 9.14. It allows unauthenticated attackers to make server-side requests to unvalidated user-supplied URLs and exposes attached third-party integration credentials. Immediate update to the latest plugin version is strongly recommended.
Azərbaycanca: CVE-2026-13700, WooMS WordPress plaginində (versiya 9.14 və əvvəlki) aşkarlanmış kritik Server-Side Request Forgery (SSRF) zəifliyidir. Bu, autentifikasiya olunmamış hücumçulara istifadəçi tərəfindən təqdim edilən URL-i yoxlamadan server sorğuları göndərməyə və üçüncü tərəf inteqrasiya məlumatlarını ifşa etməyə imkan verir. Plaginin dərhal ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What versions of the WooMS plugin are affected by CVE-2026-13700?
All versions of WooMS up to and including version 9.14 are affected by this SSRF vulnerability.
What does CVE-2026-13700 enable an attacker to do?
This vulnerability allows an unauthenticated attacker to make server-side requests to unvalidated URLs (SSRF) and expose attached third-party integration credentials.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.