Description
Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Side Request Forgery.This issue affects WordPress Image shrinker: from n/a through <= 1.1.0.
Published: 2025-12-29
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WordPress Image shrinker plugin version 1.1.0 or earlier is affected by a Server Side Request Forgery vulnerability. An attacker who can trigger the plugin’s image shrinking functionality can cause the server to initiate requests to arbitrary URLs. This flaw could allow data exfiltration or access to internal resources, as the request follows the server’s network configuration. The weakness is classified as CWE‑918. No indication is provided that the vulnerability grants authentication bypass or execution of arbitrary code, but it could be combined with other local or remote weaknesses to further compromise confidentiality or integrity.

Affected Systems

All installations of the HETWORKS WordPress Image shrinker plugin up to and including version 1.1.0. Any WordPress site that has installed this plugin and has an active upload mechanism or a user who can upload or modify images is potentially impacted.

Risk and Exploitability

The CVSS score of 4.9 suggests moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the image upload or processing function exposed by the plugin; an attacker with access to this functionality could supply a crafted URL to trigger the SSRF. No evidence is present that additional authentication is required beyond that needed to exercise the plugin’s upload feature.

Generated by OpenCVE AI on April 29, 2026 at 15:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest WordPress Image shrinker release (any version newer than 1.1.0).
  • Configure the web server or host firewall to restrict outbound HTTP/HTTPS requests from the WordPress installation to only trusted domains, thereby limiting the impact of an SSRF.
  • If the plugin is not essential, deactivate and remove it from the WordPress site to eliminate the vulnerability.

Generated by OpenCVE AI on April 29, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker allows Server Side Request Forgery.This issue affects WordPress Image shrinker: from n/a through 1.1.0. Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Side Request Forgery.This issue affects WordPress Image shrinker: from n/a through <= 1.1.0.
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Hetworks
Hetworks wordpress Image Shrinker
Wordpress
Wordpress wordpress
Vendors & Products Hetworks
Hetworks wordpress Image Shrinker
Wordpress
Wordpress wordpress

Mon, 29 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Dec 2025 16:00:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker allows Server Side Request Forgery.This issue affects WordPress Image shrinker: from n/a through 1.1.0.
Title WordPress WordPress Image shrinker plugin <= 1.1.0 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Hetworks Wordpress Image Shrinker
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:32.690Z

Reserved: 2025-12-24T14:00:37.598Z

Link: CVE-2025-68893

cve-icon Vulnrichment

Updated: 2025-12-29T16:42:12.788Z

cve-icon NVD

Status : Deferred

Published: 2025-12-29T16:15:43.303

Modified: 2026-04-23T15:36:11.857

Link: CVE-2025-68893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T15:30:14Z

Weaknesses