
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0682 is a Server-Side Request Forgery (SSRF) vulnerability in the Church Admin plugin for WordPress, affecting all versions up to and including 5.0.28. The flaw stems from insufficient validation of user-supplied URLs in the audio_url parameter, allowing authenticated attackers with Administrator-level access to make arbitrary web requests from the server. It was disclosed on January 16–17, 2026, with Wordfence as the reporting CNA. The vulnerability carries a CVSS v3.1 base score of 2.2 (Low), reflecting the high privilege requirement and limited impact (Wordfence, Red Hat CVE).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and resides in two files within the Church Admin plugin: includes/functions.php (line 6297) and includes/sermon-podcast.php (line 1181), where the audio_url parameter is accepted without adequate URL validation or allowlisting (Wordfence). An authenticated attacker with Administrator privileges can supply a crafted URL to these parameters, causing the web application to issue HTTP requests to arbitrary internal or external destinations. Exploitation requires high privileges and high attack complexity, limiting the practical attack surface to compromised or malicious administrators.
Successful exploitation allows an attacker to leverage the WordPress server as a proxy to query and potentially modify information from internal services that would otherwise be inaccessible from the internet. The confidentiality impact is rated None and availability impact is None, while integrity impact is Low — meaning an attacker could interact with internal endpoints to alter data in limited ways. The vulnerability does not directly expose sensitive data or cause service disruption, but could be used to probe internal network topology or interact with metadata services in cloud-hosted environments (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-0682. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement for Administrator-level authentication and high attack complexity (Wordfence).
audio_url parameter is accepted (corresponding to sermon-podcast.php line 1181 or functions.php line 6297).http://169.254.169.254/latest/meta-data/ for cloud metadata, or http://internal-service:8080/admin) as the value of the audio_url parameter.audio_url value, causing the WordPress server to issue an HTTP request to the attacker-specified destination.audio_url parameter.169.254.169.254), or unexpected external hosts, originating from the web server process.Users should update the Church Admin plugin to a version beyond 5.0.28, as a patch was made available via the WordPress plugin repository (changeset 3440847). The fix can be reviewed in the plugin's trunk source for functions.php and sermon-podcast.php. As a temporary workaround, restrict Administrator access to trusted users only and consider using a web application firewall (WAF) to block SSRF-indicative request patterns (Wordfence, WordPress Changeset).
The vulnerability received limited industry attention given its low CVSS score and high privilege requirement. Wordfence disclosed the issue through their threat intelligence platform, and it was picked up by automated vulnerability aggregators including VulDB, Vulners, and CIRCL. A brief technical write-up was published by Infinit Security (Infinit Security). No significant researcher commentary or broader media coverage has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."