Executive brief
Fediverse Embeds is a WordPress plugin used to display social media posts from the Fediverse on websites. A security flaw in the plugin allows any anonymous visitor to use the website as a proxy to access other internal or external servers. This could lead to the exposure of sensitive internal data or allow attackers to hide their identity by routing malicious traffic through the affected website.
Technical details
The Fediverse Embeds plugin for WordPress (prior to version 1.5.8) registers an unauthenticated REST route 'ftf/media-proxy' with a permission callback that always returns true. This endpoint accepts a base64-encoded URL and passes it directly to the 'wp_remote_get()' function without validating the destination against an allowlist or checking for private IP ranges. Because the full response body from the requested URL is echoed back to the caller, an attacker can perform a full-read Server-Side Request Forgery (SSRF) to scan internal networks or access metadata services. The issue was addressed in version 1.5.8 by implementing host and IP validation.
Affected products
- Stefan Bohacek Fediverse Embeds <= 1.5.7
Timeline
- 2026-05-14: disclosed: Initial report to maintainer
- 2026-05-15: patched: Version 1.5.8/1.5.9 released on WordPress.org
- 2026-06-11: advisory: CVE published to NVD