N/A
2026-04-01< 5.7.0
Webmention <= 5.6.2 - Authenticated (Subscriber+) Server-Side Request Forgery
Minimum safe version
5.7.0
Update to 5.7.0 or later to address 4 fixable vulnerabilities
Webmention <= 5.6.2 - Authenticated (Subscriber+) Server-Side Request Forgery
WordPress Webmention Plugin <= 5.6.2 is vulnerable to Server Side Request Forgery (SSRF)
WordPress Webmention Plugin <= 4.0.8 is vulnerable to Cross Site Scripting (XSS)
Webmention <= 4.0.8 - Reflected Cross-Site Scripting via 'replytocom'