CVE-2026-13700Disclosure

LOWCVSS 5.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to disclose the configured integration credentials when the relevant data-sync feature is enabled.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-17: 3Technical Details · 2026-08-17: 308-17
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-13700 The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration cre… https://www.cve.org/CVERecord?id=CVE-2026-13700

    Post summary

    The entry notes a server‑side request forgery flaw in WooMS WordPress plugin (v≤9.14) but offers no PoC, exploit code, patch or evidence of active exploitation.

    000101.0K
    58.0K followersView on X
  • NewNormal Security@NewScanTeam
    Disclosure

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 17 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 🖥️ Go pprof left on a public listener — heap dumps, and the app's own access code, with no login (SiYuan CVE-2026-74799) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: ⚡ MCP code interpreter escaping its sandbox — RCE on the MCP host from one prompt injection (pptr-mcp CVE-2026-19958, Jij-MCP-Server CVE-2026-19964) 📦 WordPress plugin leaking its stored integration credentials to any URL an anonymous visitor names (WooMS CVE-2026-13700) 𝗔𝗱𝗱𝗲𝗱 𝘁𝗼 𝗡𝗲𝘄𝗦𝗰𝗮𝗻 𝗣𝗿𝗼 — 𝗼𝘂𝘁-𝗼𝗳-𝗯𝗮𝗻𝗱: 🔀 MCP tool fetching a caller-supplied URL — internal services and cloud metadata via the agent's own tool call (facebook-ads-mcp-server CVE-2026-19956, graphlit-mcp-server CVE-2026-19957, mcp-florence2 CVE-2026-19984, PromptShopMCP CVE-2026-74842) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #MCP #CSO #REDTEAM

    Post summary

    NewNormal Security announces several newly identified CVEs with technical details like RCE and credential leakage, but does not provide PoC, exploit code, patches, or evidence of active exploitation.

    0000067
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13700 WooMS WordPress Plugin Vulnerable to SSRF and Credential Disclosure https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13700 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    CVE-2026-13700 is a newly disclosed vulnerability in the WooMS WordPress plugin, allowing SSRF and credential disclosure, with references to detailed information via external links.

    0000097
    4.1K followersView on X

Explore more