WordPress · Auto Upload Images · CVE-2026-12106
**Name of the Vulnerable Software and Affected Versions**
Auto Upload Images versions prior to 3.3.3
**Description**
This issue is a Limited Server-Side Request Forgery (SSRF), a flaw that allows a server to be coerced into making requests to an unintended location. Authenticated attackers with contributor-level access or higher can initiate web requests to arbitrary locations from the web application. The flaw exists in the `downloadImage()` function because the plugin utilizes `wp remote get()` instead of `wp safe remote get()`. Additionally, the `validate()` method only rejects URLs matching the site's own hostname, failing to block requests to loopback, private, or link-local addresses such as `127.0.0.1`, `10.0.0.0/8`, or `169.254.169.254`. This can be triggered by embedding a crafted `<img>` tag with a `src` attribute pointing to internal network hosts within post content.
**Recommendations**
Update to a version newer than 3.3.2.
As a temporary workaround, restrict the ability of users with contributor-level access to submit post content containing `<img>` tags until the update is applied.