PT-2026-26856 · WordPress · Wordpress Content Syndication Toolkit

Youcef Hamdani

·

Published

2026-03-21

·

Updated

2026-03-22

·

CVE-2026-3478

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress Content Syndication Toolkit plugin versions prior to 1.4
Description The WordPress Content Syndication Toolkit plugin is susceptible to a Server-Side Request Forgery issue. The plugin registers an unauthenticated proxy endpoint, ''wp ajax nopriv redux p'', which accepts a URL from the url GET parameter without validation. This parameter is passed to wp remote request(), lacking built-in SSRF protection. The absence of authentication checks, nonce verification, and URL restrictions allows attackers to make web requests to arbitrary locations from the web application, potentially enabling access to internal services, network scanning, and interaction with cloud metadata endpoints.
Recommendations Update to version 1.4 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-3478

Affected Products

Wordpress Content Syndication Toolkit