Junglewise Threat Intelligence

CVE-2026-11370: JoomUnited WP Meta SEO SSRF via new_link parameter

CVE-2026-11370 · Severity: medium · CVSS 6.4 · Published 2026-06-24

Vendors: JoomUnited.

Executive brief

WP Meta SEO is a WordPress plugin used to manage search engine optimization and broken links. A security flaw allows logged-in users with contributor-level access or higher to force the website to make unauthorized requests to internal or external servers. This could be used to scan internal networks, access sensitive cloud metadata, or interact with internal services that are not normally accessible from the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the WP Meta SEO plugin due to insufficient validation of the 'new_link' parameter. Authenticated attackers with contributor-level permissions or higher can exploit this to make the server initiate outbound HTTP requests to arbitrary IP addresses or domains. The application reflects the HTTP response status code back in an AJAX JSON response, effectively creating an enumeration oracle. This can be leveraged to scan internal network hosts, query local services, or access cloud provider metadata services (e.g., AWS/GCP metadata endpoints). The vulnerability is present in all versions up to and including 4.5.18.

Affected products

  • JoomUnited WP Meta SEO up to, and including, 4.5.18

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory

References

Related threats