CVE-2026-83543 Details
Description
The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.
A server-side request forgery (SSRF) vulnerability has been identified in the Greenshift WordPress plugin, affecting versions prior to 13.2.0. The vulnerability arises because the plugin does not properly validate user-supplied URLs before fetching them server-side. This flaw allows users with contributor-level access and above to make the server send requests to arbitrary hosts and read the responses. The issue is particularly concerning as it could potentially be exploited to access internal resources, although testing indicated that WordPress core's request wrapper blocks such attempts.
Users are advised to update the Greenshift WordPress plugin to version 13.2.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 5, 2026CISA-ADP
Assessed Sep 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/902e46ad-e577-4a3e-be19-a3bcc75ece77/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Greenshift | < 13.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 6, 2026 | CVE Modified | CISA-ADP |
| Sep 5, 2026 | New CVE Received | [email protected] |
Volerion