Sceawere
Vulnerability Detail
CVE-2026-39728UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated SSRF in Instapage Plugin
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 16h ago
- Vendor
- instapagedev
- Product
- Instapage Plugin
- Attack Type
- CWE-918 Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Server Side Request Forgery (SSRF) in Instapage Plugin <= 3.7.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-06T09:17:45.140Z",
"pubdate": "2026-10-06T09:17:45.140Z",
"executiveSummary": "The Instapage Plugin for WordPress, in versions up to and including 3.7.2, contains a critical Server-Side Request Forgery (SSRF) vulnerability. This vulnerability arises from improper validation of user-supplied input when the plugin processes external resource requests.\nThe flaw allows an unauthenticated remote attacker to force the affected WordPress server to perform arbitrary HTTP requests to internal or external destinations. By abusing this functionality, an attacker can bypass network security boundaries, interact with internal services that are not exposed to the public internet, or probe the local network infrastructure.\nThe impact includes potential unauthorized access to sensitive internal metadata services (such as those used in cloud environments like AWS or GCP), internal API endpoints, or private network assets. Given that the vulnerability does not require authentication, it represents a significant security risk for any WordPress site utilizing the affected versions. Exploitation is trivial and does not require elevated privileges, making it a high-priority concern for remediation.",
"technicalDetails": "The vulnerability resides in the request handling mechanism of the Instapage Plugin where input parameters are insufficiently sanitized before being utilized in server-side request functions. In versions 3.7.2 and below, the plugin fails to implement adequate allowlisting or proper URL parsing logic to prevent the application from making requests to unauthorized destinations.\nThe attack flow commences when an unauthenticated actor submits a crafted HTTP request to a specific endpoint exposed by the plugin. This request contains a parameter intended to define the target of a server-side resource fetch. Because the plugin logic executes this fetch without validating that the target URL conforms to expected schemas or destinations, the server acts as a proxy for the attacker.\nSpecifically, the component responsible for processing plugin-related webhooks or remote configuration calls accepts the user-controlled input and passes it directly to a low-level HTTP client library or native PHP function like 'wp_remote_get'. By providing a local IP address or a loopback address (e.g., 127.0.0.1) as the target, the attacker can interact with services bound to 'localhost', such as database management interfaces or internal management APIs that trust traffic originating from the web server.\nFurthermore, this SSRF flaw can be utilized to perform blind exploitation, where the attacker observes timing differences or server responses to infer the existence of internal services. In cloud-hosted WordPress environments, this is particularly dangerous as it allows for the exfiltration of sensitive security credentials or identity tokens from the cloud provider's Instance Metadata Service (IMDS).\nBecause the execution happens within the context of the WordPress process, the attacker leverages the server's identity to bypass firewall rules that restrict external access to the internal network. The vulnerability is characterized by a complete lack of authentication checks for the affected endpoint, permitting any remote user to initiate the malicious request sequence without interaction from legitimate administrators."
}