CVE-2026-0807
HIGHFrontis Blocks <= 1.1.6 - Unauthenticated SSRF via 'url' Parameter
Title source: llmDescription
The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.6. This is due to insufficient restriction on the 'url' parameter in the 'template_proxy' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application via the '/template-proxy/' and '/proxy-image/' endpoint.
References (4)
Core 4
Scores
CVSS v3
7.2
EPSS
0.0032
EPSS Percentile
24.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
wpmessiah/Frontis Blocks — Block Library for the Block Editor
< 1.1.6
Published
Jan 24, 2026
Tracked Since
Feb 18, 2026