PatchSiren

WooMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WooMS CVE published 2026-08-17

CVE-2026-13700

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T06:17:31.120Z and has not been modified since then. The WooMS WordPress plugin through 9.14 does not validate user-supplied URLs before using them in server-side requests, allowing unauthenticated attackers to perform Server-Side Request Forgery (SSRF) and disclose configured integration credenti [truncated]