CVE Explorer
CVE-2026-3576
The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. The send_http_post() function validates the host of the provided URL against an allowlist that includes 'localhost', but critically fails to validate the URL scheme/protocol. This makes it possible fo
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Planyo online reservation system","vendor":"xtreeme","versions":[{"lessThanOrEqual":"3.0","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":7.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20 Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/problemTypes/0/descriptions/0
Source references
12 source assertions{"url":"https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/tags/2.7/ulap.php#L118"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/10
{"url":"https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/tags/2.7/ulap.php#L120"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/8
{"url":"https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/tags/2.7/ulap.php#L59"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/6
{"url":"https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/tags/2.7/ulap.php#L84"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/2
{"url":"https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/tags/2.7/ulap.php#L96"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/4
{"url":"https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/trunk/ulap.php#L118"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/9
{"url":"https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/trunk/ulap.php#L120"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/7
{"url":"https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/trunk/ulap.php#L59"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/5
{"url":"https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/trunk/ulap.php#L84"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/1
{"url":"https://plugins.trac.wordpress.org/browser/planyo-online-reservation-system/trunk/ulap.php#L96"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/3
{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3488647%40planyo-online-reservation-system&new=3488647%40planyo-online-reservation-system"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/11
{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5038d12a-e119-4ab7-aadc-69b765ae7027?source=cve"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f7758425a9c89b95faaf2613f4f06174dc14b1f96e89fd928583cec63413f5 · sha256:cc84586b97049a30… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.