Description
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
Published: 2026-08-18
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The plugin contains a subscriber‑level SSRF flaw that permits an attacker to instruct the WordPress installation to perform arbitrary HTTP or HTTPS requests to any target, including internal network services. This weakness can lead to data disclosure, credential harvesting or launching further attacks against internal components. The flaw is a classic web request forgery identified as CWE‑918.

Affected Systems

WordPress plugin "[Aotuman] Grab WeChat Articles" by apoyl with versions 2.0.1 and earlier is vulnerable. The issue exists in the plugin’s request handling code that accepts external URLs from untrusted input.

Risk and Exploitability

The CVSS score of 6.0 indicates a medium risk level. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the probability of exploit is uncertain but potentially significant in environments that allow the plugin to process untrusted data. The likely attack vector is through the plugin’s subscriber interface, where an attacker can supply a crafted URL to trigger the SSRF.

Generated by OpenCVE AI on August 18, 2026 at 15:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest available version of the plugin (at least 2.0.2), which removes the SSRF flaw.
  • If an upgrade cannot be performed immediately, disable or remove the plugin from the WordPress installation to eliminate the attack surface.
  • As an interim measure, restrict outbound traffic from the server or tighten the plugin’s request handling to permit only requests to trusted domains.

Generated by OpenCVE AI on August 18, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Apoyl
Apoyl [aotuman] Grab Wechat Articles
Wordpress
Wordpress wordpress
Vendors & Products Apoyl
Apoyl [aotuman] Grab Wechat Articles
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
Title WordPress [Aotuman] Grab WeChat Articles plugin <= 2.0.1 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Apoyl [aotuman] Grab Wechat Articles
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T19:48:24.345Z

Reserved: 2026-03-12T11:11:45.409Z

Link: CVE-2026-32467

cve-icon Vulnrichment

Updated: 2026-08-18T19:40:26.031Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T14:17:04.000

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-32467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:33:51Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)