THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-16600 (HIGH 7.7) — The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary inter

[NVD] CVE-2026-16600 (HIGH 7.7) — The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary inter

mednvdPublished 2026-08-29

CVE-2026-16600 CVSS: 7.7 HIGH Published: 2026-08-29T06:17:05.443

The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary internal or external URLs and read the response, resulting

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16600