CVE-2026-3478General

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3 via the redux_p AJAX action in the bundled ReduxFramework library. The plugin registers a proxy endpoint (wp_ajax_nopriv_redux_p) that is accessible to unauthenticated users. The proxy() method in the Redux_P class takes a URL directly from $_GET['url'] without any validation (the regex is set to /.*/ which matches all URLs) and passes it to wp_remote_request(), which does not have built-in SSRF protection like wp_safe_remote_request(). There is no authentication check, no nonce verification, and no URL restriction. The response from the requested URL is then returned to the attacker, making this a full-read SSRF. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application, which can be used to query and modify information from internal services, scan internal network ports, or interact with cloud metadata endpoints.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-21); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-22: 1Mentions · 2026-03-31: 1PoC Mentioned / Linked · 2026-03-31: 1Exploit Tool / Code · 2026-03-31: 1Technical Details · 2026-03-21: 2Technical Details · 2026-03-31: 103-2103-2203-31
Signal classification3 categories
General
250.0%
Disclosure
125.0%
PoC
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure1General1
2026-03-221
General1
2026-03-311
PoC1
Full discourse4 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-3478-content-syndication-toolkit-version-1-3-high-vulnerability-proof-of-concept CVE-2026-3478 #WordPress plugin #vulnerability content-syndication-toolkit https://atomicedge.io/?p=6570 #cybersecurity #wordpressfirewall #wordpresssecuri…

    Post summary

    The post shares a proof‑of‑concept exploit for CVE‑2026‑3478 affecting the WordPress Content Syndication Toolkit v1.3, but offers no evidence of active attacks, patches, or a false‑positive claim.

    0202061
    9 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-3478 - benmoody - Content Syndication Toolkit - https://www.redpacketsecurity.com/cve-alert-cve-2026-3478-benmoody-content-syndication-toolkit/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3478 #benmoody #content-syndication-toolkit

    Post summary

    The tweet announces a CVE alert but does not contain specific technical details, exploit code, or evidence of active exploitation.

    0000058
    3.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3478 Server-Side Request Forgery in WordPress Content Syndication Toolkit Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3478

    Post summary

    CVE-2026-3478 is a Server‑Side Request Forgery vulnerability affecting the WordPress Content Syndication Toolkit Plugin, as reported on vulmon.com.

    0000034
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3478 The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3 via the redux_p AJAX action … https://www.cve.org/CVERecord?id=CVE-2026-3478

    Post summary

    The text announces a Server‑Side Request Forgery (SSRF) vulnerability in the Content Syndication Toolkit WordPress plugin (CVE‑2026‑3478) with affected versions noted, but it provides no exploit details, patch information, or active exploitation evidence.

    0000040
    56.8K followersView on X

Explore more