CVE-2026-12095 Details
Description
The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The script echoes internal API response data (specifically the value of any 'auth' key in a JSON response body) verbatim back to the attacker's browser, enabling direct exfiltration of responses from internal services such as cloud instance metadata endpoints.
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Kargo Takip plugin for WordPress, affecting all versions through 1.2. The vulnerability arises from the 'api_url' parameter, allowing unauthenticated attackers to send web requests to arbitrary locations via the web application. This could be exploited to query and modify information from internal services. The plugin echoes internal API response data, specifically any 'auth' key in a JSON response, back to the attacker's browser. This behavior enables direct exfiltration of data from internal services, such as cloud instance metadata endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://plugins.trac.wordpress.org/browser/kargo-takip/trunk/ui/decodeandview.php#L21 | [email protected] | Broken LinkSource CodeVendor |
| https://plugins.trac.wordpress.org/browser/kargo-takip/trunk/ui/decodeandview.php#L28 | [email protected] | Broken LinkSource CodeVendor |
| https://plugins.trac.wordpress.org/browser/kargo-takip/trunk/ui/decodeandview.php#L3 | [email protected] | Broken LinkSource CodeVendor |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/79d91300-b6b7-4c3f-89b1-c48b9e47c415?source=cve | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Kargo Takip | <= 1.2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion