What is CVE-2026-6089?
The WP CTA plugin for WordPress up to version 2.1.2 contains a Server-Side Request Forgery vulnerability via the 'sticky_s_media' parameter when importing JSON files. Attackers can craft JSON data to force the server to make unauthorized internal requests, so immediate plugin update is recommended.
Azərbaycanca: WordPress WP CTA pluqinin 2.1.2-yə qədər versiyalarında JSON fayllarının idxalı zamanı 'sticky_s_media' parametri vasitəsilə Server-Side Request Forgery (SSRF) boşluğu aşkar edilib. Təcavüzkar xüsusi hazırlanmış JSON yükləyərək server daxilində icazəsiz sorğular göndərə bilər, dərhal pluqin yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ1
What file format does an attacker use to exploit the CVE-2026-6089 vulnerability in the WP CTA plugin?
An attacker exploits the SSRF vulnerability via the 'sticky_s_media' parameter by uploading specially crafted JSON files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.