CVE-2026-13700
WooMS <= 9.14 - Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to disclose the configured integration credentials when the relevant data-sync feature is enabled.
| Vendor | unknown |
| Product | wooms |
| Published | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wooms
Be the first to know when new unknown vulnerabilities affecting unknown wooms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WooMS
0 โค 9.14
References
Credits
dangnosuy WPScan