Server-Side Request Forgery (SSRF) vulnerability in Alobaidi Extend Link extend-link allows Server Side Request Forgery.This issue affects Extend Link: from n/a through <= 2.0.0.
History

Fri, 20 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Alobaidi
Alobaidi extend Link
Wordpress
Wordpress wordpress
Vendors & Products Alobaidi
Alobaidi extend Link
Wordpress
Wordpress wordpress

Fri, 20 Feb 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Thu, 19 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in Alobaidi Extend Link extend-link allows Server Side Request Forgery.This issue affects Extend Link: from n/a through <= 2.0.0.
Title WordPress Extend Link plugin <= 2.0.0 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2026-02-19T08:26:53.599Z

Updated: 2026-02-19T20:37:54.630Z

Reserved: 2026-02-02T12:20:39.016Z

Link: CVE-2026-25310

cve-icon Vulnrichment

Updated: 2026-02-19T20:35:40.488Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-19T09:16:15.200

Modified: 2026-02-19T21:18:29.423

Link: CVE-2026-25310

cve-icon Redhat

No data.