Server-Side Request Forgery in Media Cleaner Plugin for WordPress
CVE-2026-4912
4.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-4912?
The Media Cleaner plugin for WordPress is susceptible to Server-Side Request Forgery due to inadequate hostname validation in the get_urls_from_html() function. This vulnerability allows authenticated users with Administrator access to initiate web requests from the application to arbitrary locations, potentially exposing internal services to unauthorized queries and actions. The flaw affects all versions of the plugin up to and including 7.0.3, highlighting the need for immediate attention and updates by site administrators.
Affected Version(s)
Media Cleaner: Clean your WordPress! 0 <= 7.0.3