What is CVE-2026-14939?
CVE-2026-14939: In Visualizer WordPress plugin versions before 4.0.6, unrestricted user-supplied URLs allow users with Contributor-level access and above to perform Server-Side Request Forgery (SSRF) against link-local instance-metadata endpoints. Immediate plugin update is recommended.
Azərbaycanca: CVE-2026-14939: Visualizer WordPress plugin-in 4.0.6 əvvəlki versiyalarında, istifadəçi tərəfindən təqdim olunan URL-in təhlükəsizlik yoxlaması olmadığı üçün Contributor və yuxarı səviyyəli istifadəçilərə Server-Side Request Forgery (SSRF) hücumu ilə link-local instance-metadata endpoint-lərə sorğu göndərməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of the Visualizer WordPress plugin are affected by CVE-2026-14939?
The vulnerability exists in Visualizer plugin versions before 4.0.6.
What user privilege level does the CVE-2026-14939 SSRF attack affect?
The vulnerability affects users with Contributor-level access and above.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.