PT-2026-57724 · Bdthemes+1 · Instant Image Generator+1

CVE-2026-57413

·

Published

2026-07-08

·

Updated

2026-07-13

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Instant Image Generator versions prior to 2.1.5
Description A Server-Side Request Forgery (SSRF) issue exists in the Instant AI Image Generator plugin for WordPress. This allows authenticated attackers with Subscriber-level access and above to initiate web requests to arbitrary locations from the web application. Such requests can be used to query and modify information from internal services.
Recommendations Update the plugin to a version newer than 2.1.4.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57413

Affected Products

Instant Image Generator
Mage Ai