validate_restricted_url of the component Webhook/Notification. The manipulation leads to time-of-check time-of-use.This vulnerability is traded as CVE-2026-7724. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Upgrading the affected component is advised.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
SOCIAL SHARE CARD GENERATOR