Limited Server-Side Request Forgery in Auto Upload Images Plugin for WordPress
CVE-2026-12106
6.4MEDIUM
What is CVE-2026-12106?
The Auto Upload Images plugin for WordPress allows authenticated attackers with contributor-level access or higher to exploit a limited server-side request forgery vulnerability. This occurs via the downloadImage function, where attackers can craft <img> tags with a src attribute that points to internal or arbitrary network hosts. The plugin inadequately validates URLs, permitting requests to private IP addresses that should be restricted. This can lead to potential exploitation where sensitive information may be exposed or internal systems accessed.
Affected Version(s)
Auto Upload Images 0 <= 3.3.2