[CVE-2026-16600] The SmartAIPress WordPress plugin through 1.2.0 does not per

CVE-2026-16600 | CVSS: 7.7 | 严重级别: HIGH

The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary internal or external URLs and read the response, resulting in a full-read Server-Side Request Forgery.

参考链接:
https://wpscan.com/vulnerability/66d2dc2d-fe77-4d34-bfca-d47b086a9c96/

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部