Server-Side Request Forgery Vulnerability in Ali Irani Auto Upload Images
CVE-2025-49985
4.9MEDIUM
What is CVE-2025-49985?
The Ali Irani Auto Upload Images plugin for WordPress has been identified with a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows unauthorized users to send crafted requests from the server, potentially exposing sensitive data or interacting with internal services inappropriately. The vulnerability affects versions from n/a through 3.3.2, posing significant risks to website security if not addressed promptly.
Affected Version(s)
Auto Upload Images <= 3.3.2