PatchSiren

airani CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM airani CVE published 2026-09-18

CVE-2026-12106

The Auto Upload Images plugin for WordPress has a Limited Server-Side Request Forgery vulnerability in all versions up to, and including, 3.3.2. Authenticated attackers with contributor-level access can make web requests to arbitrary locations. The plugin's use of wp_remote_get() instead of wp_safe_remote_get() and incomplete URL validation allow requests to private, loopback, or link-local addresses.