Server-Side Request Forgery in Media Cleaner Plugin for WordPress
CVE-2026-4912

4.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 July 2026

What is CVE-2026-4912?

The Media Cleaner plugin for WordPress is susceptible to Server-Side Request Forgery due to inadequate hostname validation in the get_urls_from_html() function. This vulnerability allows authenticated users with Administrator access to initiate web requests from the application to arbitrary locations, potentially exposing internal services to unauthorized queries and actions. The flaw affects all versions of the plugin up to and including 7.0.3, highlighting the need for immediate attention and updates by site administrators.

Affected Version(s)

Media Cleaner: Clean your WordPress! 0 <= 7.0.3

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lucsob
.