Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.7

CVE-2026-16600: SmartAIPress plugin lets logged-in users fetch any URL

CVE-2026-16600 · published 5 days ago
Summary

The SmartAIPress plugin for WordPress (versions up to 1.2.0) lets anyone with a basic account tell the website to contact any web address and see the reply. This could expose internal systems or private data. Update the plugin or disable the feature until a fix is released.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
unknown smartaipress <= 1.2.0
Original advisory text
SmartAIPress <= 1.2.0 - Subscriber+ Server-Side Request Forgery via smartaipress_openai_upload_and_set_featured_image
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary internal or external URLs and read the response, resulting in a full-read Server-Side Request Forgery.
Severity
7.7 High
Exploitation
EPSS <1%
Type
CWE-918Server-Side Request Forgery (SSRF)
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-16600 · MITRE
Monitor software like this
Free during beta