high
CVE-2026-13700
WooMS unauthenticated SSRF in the data-sync feature - the plugin attaches its stored third-party integration credentials to a request aimed at an attacker-supplied URL, so the credentials leak to the attacker's host
- Severity
- high
- Affected product
- wooms
- Affected versions
- wooms ≤ 9.14
- Fixed in
- wooms no fixed release yet - restrict the sync endpoint
- Added to NewScan
- 2026-08-17
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints wooms from its response and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →