Home

Description

The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.28.0. This makes it possible for authenticated attackers, with Administrator-level access, to make web requests to initiate arbitrary outbound requests from the application and read the returned response content. Successful exploitation was confirmed by receiving and observing response data from an external Collaborator endpoint.

PUBLISHED Reserved 2026-02-10 | Published 2026-03-21 | Updated 2026-04-08 | Assigner Wordfence




LOW: 3.8CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-918 Server-Side Request Forgery (SSRF)

Product status

Default status
unaffected

Any version
affected

Timeline

2026-03-20:Disclosed

Credits

Phap Nguyen Anh finder

References

www.wordfence.com/...-bb36-479e-b342-36d2ca778ce1?source=cve

plugins.trac.wordpress.org/...iliatepro/trunk/Base.class.php

plugins.trac.wordpress.org/...pro/tags/1.28.0/Base.class.php

cve.org (CVE-2026-2290)

nvd.nist.gov (CVE-2026-2290)

Download JSON