Executive brief
The Fediverse Embeds plugin for WordPress, which allows websites to display content from decentralized social networks, contains a security flaw in its media-handling component. An unauthorized attacker can use the website as a proxy to access internal systems or private data that are not normally accessible from the internet. This could lead to the exposure of sensitive configuration files, cloud metadata, or other private internal services.
Technical details
The Fediverse Embeds plugin for WordPress is vulnerable to an unauthenticated full-read Server-Side Request Forgery (SSRF) via its media-proxying REST API endpoint. The vulnerability exists because the `/ftf/media-proxy` endpoint accepts a base64-encoded `url` parameter and fetches the content without validating if the destination is an external or internal address. An attacker can exploit this by sending a crafted request to the REST route, allowing them to bypass network firewalls to scan internal ports, access cloud metadata services (e.g., 169.254.169.254), or read sensitive data from internal web services. The issue is fixed in version 1.5.8, which implements destination validation and returns a 403 Forbidden error for restricted addresses.
Affected products
- Unknown Fediverse Embeds < 1.5.8
Timeline
- 2026-06-18: disclosed: Publicly published by researcher
- 2026-06-18: patched: Fix released in version 1.5.8
- 2026-07-09: advisory: CVE published to NVD dataset