CVE-2026-13700 - WooMS <= 9.14 - Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure
CVE ID :CVE-2026-13700
Published : Aug. 17, 2026, 6:17 a.m. | 1 hour, 12 minutes ago
Description :The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to disclose the configured integration credentials when the relevant data-sync feature is enabled.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 17, 2026, 6:17 a.m. | 1 hour, 12 minutes ago
Description :The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to disclose the configured integration credentials when the relevant data-sync feature is enabled.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...