CVE-2026-12100Patch

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the 'url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-24: 2PoC Mentioned / Linked · 2026-06-24: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-24: 206-24
Signal classification2 categories
Patch
150.0%
PoC
150.0%
Referenced assets1 URL
Full discourse2 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-12100-link-preview-version-1-0-high-vulnerability-proof-of-concept CVE-2026-12100 link-preview (CVSS Score 7.2) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge #cybe

    Post summary

    The tweet links to a proof‑of‑concept for CVE‑2026‑12100 affecting the WordPress link‑preview plugin, noting a CVSS score of 7.2; there is no evidence of active exploitation, patches, or a false‑positive claim.

    0000031
    11 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-12100 (CVSS 7.2) URL Preview plugin for WordPress vulnerable to SSRF. All versions ≤1.0 affected. Unauthenticated attackers can query/modify internal services via 'url' parameter. Patch immediately. #CVE #WordPress https://t.co/9PQgyykaLU

    Post summary

    The tweet announces that CVE-2026-12100, a high‑severity SSRF flaw in the URL Preview plugin for WordPress, requires immediate patching to prevent unauthenticated attackers from manipulating internal services.

    0000034
    50 followersView on X

Explore more