CVE-2026-25385

WordPress URL Shortify plugin <= 1.12.3 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in KaizenCoders URL Shortify url-shortify allows Server Side Request Forgery.This issue affects URL Shortify: from n/a through <= 1.12.3.


We have discovered 2,551 live websites that are affected by CVE-2026-25385.

Run a Free Instant Scan




Affected Software

Product  Url Shortify
Category Wordpress Plugins
Vulnerable Domains2,551 live websites (56% of Url Shortify install base)
Vulnerable Versions
  • from 0 through 1.12.3
Vulnerable Versions Count69 versions ( 90% of all versions)



Details

  • Published - Feb 19, 2026
  • Updated - Apr 1, 2026

Credits

  • Jitlada | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-25385
United States852 websites



Germany342 websites
GB114 websites
France94 websites
Iran93 websites
Poland61 websites
Italy59 websites
Canada57 websites
Russia53 websites
Brazil50 websites

Website Distribution by TLD

Number of websites using CVE-2026-25385
.com1,010 websites
.org199 websites
.de192 websites
.net82 websites
.co.uk49 websites
.pl42 websites
.com.br42 websites
.ru41 websites
.it41 websites
.fr40 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-25385

Top websites that are affected by CVE-2026-25385. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.org United States**,***
****.***.edu United States**,***
***************.de Germany**,***
*******************.com United States**,***
*********.net United States**,***
****.org United States**,***
********************.com Bulgaria**,***
**********.com United States**,***
****.**.cy United States***,***
****.org GB***,***
See full domain list

FAQ

A total of 2,551 websites have been identified as vulnerable to CVE-2026-25385, based on global website indexing conducted by WebTechSurvey.
The Url Shortify is affected by the CVE-2026-25385 vulnerability.
Url Shortify versions up to and including 1.12.3 are vulnerable to CVE-2026-25385.