
CVE-2026-2290 The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.28.0. This makes it possible for authen… https://www.cve.org/CVERecord?id=CVE-2026-2290
Post summary
The Post Affiliate Pro WordPress plugin is disclosed to be vulnerable to SSRF in versions up to 1.28.0, with no PoC, exploit, or patch info provided.
