Impact
The Auto Upload Images plugin for WordPress allows authenticated users with contributor or higher permissions to cause the server to issue arbitrary HTTP requests. By inserting a crafted <img> tag whose src attribute points to an internal host, an attacker can make the plugin’s downloadImage function call wp_remote_get on that address. Because the plugin only rejects URLs whose host matches the site’s own hostname and does not block private, loopback, or link‑local addresses, attackers can target internal network services such as 127.0.0.1 or 10.0.0.0/8. This flaw can be used for reconnaissance or to exfiltrate data from internal resources, and it maps to CWE‑918.
Affected Systems
The vulnerability affects the Auto Upload Images plugin for WordPress versions up to and including 3.3.2. Any WordPress site that has installed this plugin without a later fix is susceptible, regardless of additional security layers, because the flaw resides in the plugin’s core code. No further vendor or product details are supplied beyond Airani’s Auto Upload Images plugin.
Risk and Exploitability
The CVSS score of 6.4 reflects a moderate impact; the EPSS score of less than 1% indicates a low current likelihood of exploitation, and the issue is not listed in CISA’s KEV catalog. Exploitation requires valid contributor‑level credentials and the ability to submit content containing an <img> tag. Once the request is processed, the WordPress instance will perform an outbound HTTP call to the attacker‑specified internal host, potentially exposing sensitive internal services. The primary attack vector is content injection via a post or comment.
OpenCVE Enrichment