Server-Side Request Forgery Vulnerability in Auto Save Remote Images Plugin for WordPress
CVE-2025-7843
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 September 2025
What is CVE-2025-7843?
The Auto Save Remote Images (Drafts) plugin for WordPress is susceptible to server-side request forgery vulnerabilities. This issue permits authenticated attackers with Contributor-level access or higher to initiate web requests to arbitrary locations through the fetch_images() function. Such exploitation can lead to unauthorized querying and modification of internal services, compromising the security and integrity of the web application.
Affected Version(s)
Auto Save Remote Images (Drafts) * <= 1.0.9