CVE-2026-14939
Received Received - Intake

Server-Side Request Forgery in Visualizer WordPress Plugin

Vulnerability report for CVE-2026-14939, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: WPScan

Description

The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata endpoints. As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
visualizer visualizer to 4.0.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in the Visualizer WordPress plugin before version 4.0.6. It allows users with Contributor-level access or higher to supply a URL that the server will fetch without validating if it is a safe address. This can let attackers access internal cloud instance metadata, including IAM credentials, on cloud-hosted sites.

Detection Guidance

Check if the Visualizer WordPress plugin version is below 4.0.6. Inspect server logs for unusual outbound requests to link-local or metadata endpoints. Look for Contributor-level users making unexpected HTTP requests.

Impact Analysis

If you use the Visualizer plugin on a cloud-hosted WordPress site and have users with Contributor-level access or higher, an attacker could exploit this to retrieve sensitive cloud instance metadata, such as IAM credentials. This could lead to unauthorized access to your cloud environment and potential data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to cloud instance metadata, including IAM credentials, which may result in data breaches. Such breaches could violate GDPR's data protection requirements and HIPAA's safeguards for protected health information, potentially leading to non-compliance and legal penalties.

Mitigation Strategies

Update the Visualizer plugin to version 4.0.6 or higher immediately. Restrict Contributor-level users from making server-side requests. Monitor network traffic for suspicious outbound connections to metadata endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14939. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart