Signal is active with 3 mentions in latest observed window
Immediate actions
Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to disclose the configured integration credentials when the relevant data-sync feature is enabled.
CVE-2026-13700 The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration cre… https://www.cve.org/CVERecord?id=CVE-2026-13700
Post summary
The entry notes a server‑side request forgery flaw in WooMS WordPress plugin (v≤9.14) but offers no PoC, exploit code, patch or evidence of active exploitation.
NewNormal Security turns the last 24 hours of CVEs into new detections, every day.
𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 17 Aug 2026
𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan:
🖥️ Go pprof left on a public listener — heap dumps, and the app's own access code, with no login (SiYuan CVE-2026-74799)
𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆:
⚡ MCP code interpreter escaping its sandbox — RCE on the MCP host from one prompt injection (pptr-mcp CVE-2026-19958, Jij-MCP-Server CVE-2026-19964)
📦 WordPress plugin leaking its stored integration credentials to any URL an anonymous visitor names (WooMS CVE-2026-13700)
𝗔𝗱𝗱𝗲𝗱 𝘁𝗼 𝗡𝗲𝘄𝗦𝗰𝗮𝗻 𝗣𝗿𝗼 — 𝗼𝘂𝘁-𝗼𝗳-𝗯𝗮𝗻𝗱:
🔀 MCP tool fetching a caller-supplied URL — internal services and cloud metadata via the agent's own tool call (facebook-ads-mcp-server CVE-2026-19956, graphlit-mcp-server CVE-2026-19957, mcp-florence2 CVE-2026-19984, PromptShopMCP CVE-2026-74842)
Test your stack with NewScan — free, self-hosted:
https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve
#infosec#AppSec#MCP#CSO#REDTEAM
Post summary
NewNormal Security announces several newly identified CVEs with technical details like RCE and credential leakage, but does not provide PoC, exploit code, patches, or evidence of active exploitation.
CVE-2026-13700
WooMS WordPress Plugin Vulnerable to SSRF and Credential Disclosure
https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13700
Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3
Post summary
CVE-2026-13700 is a newly disclosed vulnerability in the WooMS WordPress plugin, allowing SSRF and credential disclosure, with references to detailed information via external links.