MEDIUM
airani
CVE published 2026-09-18
CVE-2026-12106
The Auto Upload Images plugin for WordPress has a Limited Server-Side Request Forgery vulnerability in all versions up to, and including, 3.3.2. Authenticated attackers with contributor-level access can make web requests to arbitrary locations. The plugin's use of wp_remote_get() instead of wp_safe_remote_get() and incomplete URL validation allow requests to private, loopback, or link-local addresses.