CVE-2026-12095Disclosure

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The script echoes internal API response data (specifically the value of any 'auth' key in a JSON response body) verbatim back to the attacker's browser, enabling direct exfiltration of responses from internal services such as cloud instance metadata endpoints.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-24: 2PoC Mentioned / Linked · 2026-06-24: 1Technical Details · 2026-06-24: 206-24
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets1 URL
Full discourse2 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-12095-kargo-takip-version-1-2-high-vulnerability-proof-of-concept CVE-2026-12095 kargo-takip (CVSS Score 7.2) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge #cybers

    Post summary

    A proof‑of‑concept for CVE‑2026‑12095, affecting the WordPress plugin kargo‑takip version 1.2, has been published, but no exploit tools, active attacks, patches, or detailed technical description beyond a CVSS score are disclosed.

    0000028
    11 followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH: CVE-2026-12095 (CVSS 7.2) - Kargo Takip WordPress plugin vulnerable to SSRF. Unauthenticated attackers can query internal services & exfiltrate data. Affects all versions ≤1.2. #CVE #Vulnerability #PatchNow #WordPress https://t.co/3lcOxCYqrQ

    Post summary

    A new SSRF vulnerability (CVE-2026-12095) affecting Kargo Takip WordPress plugin versions ≤1.2 is disclosed, with CVSS 7.2, allowing unauthenticated attackers to query internal services and exfiltrate data.

    0000031
    50 followersView on X

Explore more