← All CVEs NewScan detects
high

CVE-2026-13700

WooMS unauthenticated SSRF in the data-sync feature - the plugin attaches its stored third-party integration credentials to a request aimed at an attacker-supplied URL, so the credentials leak to the attacker's host

Severity
high
Affected product
wooms
Affected versions
wooms ≤ 9.14
Fixed in
wooms no fixed release yet - restrict the sync endpoint
Added to NewScan
2026-08-17
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints wooms from its response and reports this CVE when the detected version falls inside the affected range below.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →