Junglewise Threat Intelligence

CVE-2026-39521: Nelio Software Nelio Content SSRF in WordPress plugin

CVE-2026-39521 · Severity: medium · CVSS 4.9 · Published 2026-04-08

Executive brief

Nelio Content is a WordPress plugin used for managing editorial calendars and social media scheduling. A security vulnerability in this plugin could allow an attacker with basic contributor-level access to force the web server to make unauthorized requests to internal or external systems. This could lead to the exposure of sensitive internal information or be used to bypass security controls protecting other services on the same network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Nelio Content plugin for WordPress (versions <= 4.3.1). The flaw allows an authenticated attacker with 'Contributor' or higher privileges to induce the server to make requests to arbitrary domains. This occurs due to insufficient validation of user-supplied URLs within the plugin's functionality. An attacker can leverage this to scan internal network resources, access metadata services, or interact with other internal APIs that are not intended to be public-facing. The issue is mitigated by a high attack complexity (AC:H) and requires valid low-level credentials. A fix is available in version 4.3.2.

Affected products

  • Nelio Software Nelio Content <= 4.3.1

Timeline

  • 2026-02-17: other: Vulnerability reported by Steven Julian
  • 2026-03-19: advisory: Patchstack published advisory and assigned PSID 7607ce1a513a
  • 2026-04-08: disclosed: CVE-2026-39521 published to NVD
  • 2026-04-08: patched: Version 4.3.2 released to address the vulnerability

References

Related threats