Plugin Vulnerability Hub
Plugin 3 known issues Latest disclosed Apr 01, 2026

Webmention Vulnerabilities

Review known vulnerability records for the WordPress plugin Webmention (`webmention`), including severity, CVE references, affected versions, and patch status.

Known Records
3
High or Critical
1
Linked CVEs
2
Last Updated
Apr 01, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Webmention so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
3 records include a published patch path.
Severity Mix
0 critical and 1 high severity finding.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Webmention

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-0688
Webmention <= 5.6.2 - Authenticated (Subscriber+) Server-Side Request Forgery

The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 via the 'Tools::read' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitra...

Published
Apr 01, 2026
Patched Release
5.7.0
Affected Versions
Versions up to 5.6.2
Next Step
Update to 5.7.0 or newer if supported.
Plugin High Patched: Yes CVE-2026-0686
Webmention <= 5.6.2 - Unauthenticated Blind Server-Side Request Forgery

The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 in the 'MF2::parse_authorpage' function via the 'Receiver::post' function. This makes it possible for unauthenticated attackers to make web requests to arb...

Published
Apr 01, 2026
Patched Release
5.7.0
Affected Versions
Versions up to 5.6.2
Next Step
Update to 5.7.0 or newer if supported.
Plugin Medium Patched: Yes
Webmention <= 4.0.8 - Reflected Cross-Site Scripting via 'replytocom'

The Webmention plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘replytocom’ parameter in versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...

Published
Mar 08, 2023
Patched Release
4.0.9
Affected Versions
Versions up to 4.0.8
Next Step
Update to 4.0.9 or newer if supported.