LIVE · cybersecurity feed
Live wire
cve recordlow

CVE-2026-2290

Published
CVSS3.8
Severitylow
WeaknessCWE-918
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Description

The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.28.0. This makes it possible for authenticated attackers, with Administrator-level access, to make web requests to initiate arbitrary outbound requests from the application and read the returned response content. Successful exploitation was confirmed by receiving and observing response data from an external Collaborator endpoint.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-2290

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-2290.