CVE-2026-10526
Received Received - Intake

Blind SSRF in EmbedPress WordPress Plugin

Vulnerability report for CVE-2026-10526, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: WPScan

Description

The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind Server-Side Request Forgery).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
embedpress embedpress to 4.6.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a blind Server-Side Request Forgery (SSRF) in the EmbedPress WordPress plugin before version 4.6.1. It allows unauthenticated attackers to trick the site into making HTTP requests to internal hosts or services that WordPress core URL validation does not cover.

Detection Guidance

To detect this vulnerability, monitor for unusual outbound HTTP requests from your WordPress server, especially to internal or unexpected hosts. Check server logs for requests to unauthenticated endpoints like /wp-json/embedpress/v1/preview or similar paths associated with the EmbedPress plugin. Use network monitoring tools to inspect traffic originating from the WordPress server.

Impact Analysis

An attacker could exploit this to access internal systems, exfiltrate data, or perform unauthorized actions on your behalf. It may also lead to further attacks if internal services are compromised.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR (data protection) and HIPAA (health data privacy) requirements. Compliance may be compromised if sensitive data is exposed.

Mitigation Strategies

Immediately update the EmbedPress plugin to version 4.6.1 or later. If an update is unavailable, consider disabling or uninstalling the plugin until a patch is released. Restrict outbound server traffic using a firewall to block unauthorized requests to internal hosts. Review server logs for signs of exploitation and investigate any suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10526. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart