All verified exploits

CVE-2026-0686 Webmention Plugin Unauthenticated SSRF

Deterministic high WordPress Added cve-verified-cve-2026-0686

Detects WordPress instances running the Webmention plugin version 5.6.2 or earlier, where the MF2::parse_authorpage() function uses wp_remote_get() instead of wp_safe_remote_get() when fetching author page URLs during Webmention processing. An unauthenticated attacker can make the server fetch internal URLs (cloud metadata, localhost services, internal APIs) by sending a crafted Webmention. The fix in 5.7.0 switches to wp_safe_remote_get() which blocks internal/private IP requests.

Related WordPress exploits

Is your app exploitable through CVE-2026-0686?

Scan your domain free