CVE-2026-7049Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 12.5.0.1 via the scan_video. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The SSRF is blind because fetched response bodies are only parsed internally for YouTube/Vimeo patterns and are never returned to the attacker.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-02: 3Technical Details · 2026-05-02: 305-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7049 The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 12.5.0.1 … https://www.cve.org/CVERecord?id=CVE-2026-7049

    Post summary

    The text announces a Server‑Side Request Forgery vulnerability in PixelYourSite Pro WordPress plugin, detailing affected versions and the type of flaw, but offers no PoC, exploit, or mitigation information.

    00010248
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7049 The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 12.5.0.1 … https://www.cve.org/CVERecord?id=CVE-2026-7049 ----- Traducción: CVE-2026-7049 El … http://infoflow.cloud`

    Post summary

    The post announces that PixelYourSite Pro before version 12.5.0.1 is vulnerable to Server-Side Request Forgery, linking to the official CVE record.

    0000037
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7049 Server-Side Request Forgery in PixelYourSite Pro WordPress Plugin Versions Up To 12.5.0.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7049

    Post summary

    The text announces a Server‑Side Request Forgery vulnerability in PixelYourSite Pro WordPress Plugin affecting versions up to 12.5.0.1, with no PoC or exploitation details provided.

    0000052
    4.0K followersView on X

Explore more