Junglewise Threat Intelligence

CVE-2026-56026: Chris Carlevato utm.codes SSRF in WordPress plugin

CVE-2026-56026 · Severity: medium · CVSS 6.4 · Published 2026-06-26

Executive brief

The utm.codes plugin for WordPress, which is used to manage and track marketing links, contains a security vulnerability that could allow logged-in users with basic 'Subscriber' permissions to make the server perform unauthorized web requests. An attacker could use this to probe internal network services that are not normally accessible from the internet or to access sensitive information from other services running on the same system. This could lead to internal data exposure or further attacks against the organization's private infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the utm.codes WordPress plugin through version 1.9.0. The flaw is classified as CWE-918 and resides in how the plugin handles server-side requests. An attacker authenticated with 'Subscriber' level privileges can exploit this vulnerability to force the web server to make requests to arbitrary domains or internal IP addresses. This can be used to bypass firewalls, scan internal networks, or interact with internal services (like metadata services in cloud environments) that are otherwise unreachable from the public internet. The issue is addressed in version 1.9.1.

Affected products

  • Chris Carlevato utm.codes <= 1.9.0

Timeline

  • 2025-05-29: other: Vulnerability reported by researcher theviper17
  • 2026-06-23: advisory: Patchstack advisory published
  • 2026-06-26: disclosed: NVD publication date

References