CVE-2026-0688Disclosure

LOWCVSS 6.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 via the 'Tools::read' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-02); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-02: 1Mentions · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-08: 1Exploit Tool / Code · 2026-04-08: 1Technical Details · 2026-04-02: 104-0204-08
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-021
Disclosure1
2026-04-081
PoC1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-0688 The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 via the 'Tools::read' function. This makes … https://www.cve.org/CVERecord?id=CVE-2026-0688

    Post summary

    The snippet announces that CVE-2026-0688 is a server‑side request forgery vulnerability in the WordPress Webmention plugin up to version 5.6.2, providing the technical details but no PoC, exploit, patch, or evidence of active exploitation.

    0001094
    56.9K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-0688-webmention-version-5-6-2-medium-vulnerability-proof-of-concept CVE-2026-0688 #WordPress plugin #vulnerability webmention #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The tweet points to a proof‑of‑concept for CVE‑2026‑0688 impacting the WordPress Webmention plugin v5.6.2, with no evidence of active exploitation, patch information, or technical details of the flaw.

    0000043
    6 followersView on X

Explore more