THREAT OPS › Threat News › [NVD] CVE-2026-16600 (HIGH 7.7) — The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary inter
[NVD] CVE-2026-16600 (HIGH 7.7) — The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary inter
CVE-2026-16600 CVSS: 7.7 HIGH Published: 2026-08-29T06:17:05.443
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary internal or external URLs and read the response, resulting
Indicators of compromise
- CVE-2026-16600cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16600