Description
Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.
Published: 2026-08-13
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits a malicious actor who can influence plugin requests to force the host server to make HTTP calls to internal or external addresses. This can expose sensitive internal endpoints or exfiltrate data, potentially enabling further exploitation. The weakness is identified as CWE-918.

Affected Systems

The issue exists in versions of the Vehica Core WordPress plugin from TangibleWP up to and including 1.0.104. Only the plugin itself is affected; the WordPress core remains unaffected.

Risk and Exploitability

The CVSS score of 6 indicates moderate risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits. Exploitation requires that an attacker can send crafted requests to the plugin endpoint, and the server will follow them. The scope is confined to the host where the WordPress site runs.

Generated by OpenCVE AI on August 13, 2026 at 16:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Vehica Core plugin to version 1.0.105 or later to remove the SSRF flaw.
  • Immediately disable the plugin if an update is not yet available and the site cannot tolerate interruption of the feature, to prevent exploitation.
  • Configure the server’s firewall or use a network segmentation strategy to block outbound HTTP requests originating from the WordPress application, limiting the potential impact of SSRF.
  • Monitor network traffic and application logs for unexpected outbound requests to internal IP ranges or suspicious domains.

Generated by OpenCVE AI on August 13, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.
Title WordPress Vehica Core plugin <= 1.0.104 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:19:50.154Z

Reserved: 2026-07-27T14:00:43.007Z

Link: CVE-2026-66654

cve-icon Vulnrichment

Updated: 2026-08-13T15:19:45.638Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:09.063

Modified: 2026-08-13T16:18:45.937

Link: CVE-2026-66654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:15:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)