← العودة للجدول
CVE-2026-46697
CVE-2026-46697 — Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5
📅 2026-06-11
🟠 High 🔥 No NVD Exploit Web CVSS 7.5

📋 الوصف الكامل

Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permission_callback => __return_true that accepted a base64-encoded URL and forwarded it to wp_remote_get($url) without enforcing any allowlist. The plugin's source contained a comment block explicitly

💻 الأنظمة المتأثرة

WordPress

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-46697

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v1.5

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←