Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Scc2

#45735of 57,416
6.4Total CVSS
Vulnerabilities · 1
PT-2026-95266
6.4
2026-09-18
WordPress · Auto Upload Images · CVE-2026-12106
**Name of the Vulnerable Software and Affected Versions** Auto Upload Images versions prior to 3.3.3 **Description** This issue is a Limited Server-Side Request Forgery (SSRF), a flaw that allows a server to be coerced into making requests to an unintended location. Authenticated attackers with contributor-level access or higher can initiate web requests to arbitrary locations from the web application. The flaw exists in the `downloadImage()` function because the plugin utilizes `wp remote get()` instead of `wp safe remote get()`. Additionally, the `validate()` method only rejects URLs matching the site's own hostname, failing to block requests to loopback, private, or link-local addresses such as `127.0.0.1`, `10.0.0.0/8`, or `169.254.169.254`. This can be triggered by embedding a crafted `<img>` tag with a `src` attribute pointing to internal network hosts within post content. **Recommendations** Update to a version newer than 3.3.2. As a temporary workaround, restrict the ability of users with contributor-level access to submit post content containing `<img>` tags until the update is applied.