Sceawere

Vulnerability Detail

CVE-2026-39728UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated SSRF in Instapage Plugin

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
16h ago
Vendor
instapagedev
Product
Instapage Plugin
Attack Type
CWE-918 Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Server Side Request Forgery (SSRF) in Instapage Plugin <= 3.7.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-06T09:17:45.140Z",
  "pubdate": "2026-10-06T09:17:45.140Z",
  "executiveSummary": "The Instapage Plugin for WordPress, in versions up to and including 3.7.2, contains a critical Server-Side Request Forgery (SSRF) vulnerability. This vulnerability arises from improper validation of user-supplied input when the plugin processes external resource requests.\nThe flaw allows an unauthenticated remote attacker to force the affected WordPress server to perform arbitrary HTTP requests to internal or external destinations. By abusing this functionality, an attacker can bypass network security boundaries, interact with internal services that are not exposed to the public internet, or probe the local network infrastructure.\nThe impact includes potential unauthorized access to sensitive internal metadata services (such as those used in cloud environments like AWS or GCP), internal API endpoints, or private network assets. Given that the vulnerability does not require authentication, it represents a significant security risk for any WordPress site utilizing the affected versions. Exploitation is trivial and does not require elevated privileges, making it a high-priority concern for remediation.",
  "technicalDetails": "The vulnerability resides in the request handling mechanism of the Instapage Plugin where input parameters are insufficiently sanitized before being utilized in server-side request functions. In versions 3.7.2 and below, the plugin fails to implement adequate allowlisting or proper URL parsing logic to prevent the application from making requests to unauthorized destinations.\nThe attack flow commences when an unauthenticated actor submits a crafted HTTP request to a specific endpoint exposed by the plugin. This request contains a parameter intended to define the target of a server-side resource fetch. Because the plugin logic executes this fetch without validating that the target URL conforms to expected schemas or destinations, the server acts as a proxy for the attacker.\nSpecifically, the component responsible for processing plugin-related webhooks or remote configuration calls accepts the user-controlled input and passes it directly to a low-level HTTP client library or native PHP function like 'wp_remote_get'. By providing a local IP address or a loopback address (e.g., 127.0.0.1) as the target, the attacker can interact with services bound to 'localhost', such as database management interfaces or internal management APIs that trust traffic originating from the web server.\nFurthermore, this SSRF flaw can be utilized to perform blind exploitation, where the attacker observes timing differences or server responses to infer the existence of internal services. In cloud-hosted WordPress environments, this is particularly dangerous as it allows for the exfiltration of sensitive security credentials or identity tokens from the cloud provider's Instance Metadata Service (IMDS).\nBecause the execution happens within the context of the WordPress process, the attacker leverages the server's identity to bypass firewall rules that restrict external access to the internal network. The vulnerability is characterized by a complete lack of authentication checks for the affected endpoint, permitting any remote user to initiate the malicious request sequence without interaction from legitimate administrators."
}
CVE-2026-39728: Unauthenticated SSRF in Instapage Plugin (HIGH Severity, CVSS: 7.2) | Sceawere