{"id":"CVE-2026-14939","published":"2026-08-04T07:16:29.037","lastModified":"2026-08-04T18:16:44.060","description":"The Visualizer  WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata endpoints. As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.","cvssScore":6.8,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","cwes":["CWE-918"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/b9a6211c-3173-4dd6-8a8d-32be248762bb/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows users with Contributor-level access or higher to perform Server-Side Request Forgery (SSRF) attacks, enabling them to retrieve sensitive cloud instance metadata, including IAM credentials.","exploitability":"Exploitation requires a user with at least Contributor-level access and knowledge of the target environment. The attack is non-blind, making it relatively straightforward once conditions are met.","blast_radius":"If exploited, this could lead to unauthorized access to sensitive cloud metadata, potentially compromising the security of cloud-hosted WordPress sites.","remediation":"Update the Visualizer WordPress plugin to version 4.0.6 or higher to restrict user-supplied URLs and prevent SSRF attacks.","tags":["ssrf","wordpress","cloud","metadata"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:04:11.040Z"}}