Limited Server-Side Request Forgery in Auto Upload Images Plugin for WordPress
CVE-2026-12106

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 September 2026

What is CVE-2026-12106?

The Auto Upload Images plugin for WordPress allows authenticated attackers with contributor-level access or higher to exploit a limited server-side request forgery vulnerability. This occurs via the downloadImage function, where attackers can craft <img> tags with a src attribute that points to internal or arbitrary network hosts. The plugin inadequately validates URLs, permitting requests to private IP addresses that should be restricted. This can lead to potential exploitation where sensitive information may be exposed or internal systems accessed.

Affected Version(s)

Auto Upload Images 0 <= 3.3.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scc2
.