THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-83543 (MEDIUM 4.1) — The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.

[NVD] CVE-2026-83543 (MEDIUM 4.1) — The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.

mednvdPublished 2026-09-05

CVE-2026-83543 CVSS: 4.1 MEDIUM Published: 2026-09-05T07:17:13.280

The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-83543