Description
Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects Instant Image Generator: from n/a through <= 2.1.4.
Published: 2026-07-13
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The bdthemes Instant Image Generator WordPress plugin has a Server‑Side Request Forgery vulnerability that allows an attacker to supply arbitrary URLs to the image‑generation endpoint. When the server processes the request, it will perform HTTP requests to the supplied URL, potentially accessing internal resources or external services. This can lead to disclosure of confidential information, traversal inside internal networks, or denial of service if the endpoint is flooded. The weakness is classified as CWE‑918.

Affected Systems

Affected systems are WordPress installations that use the bdthemes Instant Image Generator plugin, version 2.1.4 and earlier. Administrators should verify the plugin version and disable or remove the plugin if it cannot be promptly updated.

Risk and Exploitability

The CVSS score of 6.4 categorizes this as a moderate‑severe vulnerability. The EPSS score of less than 1 % indicates that exploitation is currently unlikely, and the issue is not listed in the CISA KEV catalog. The most likely attack vector is an unauthenticated HTTP request to the plugin’s image‑generation endpoint from an external attacker. Successful exploitation would allow the attacker to make outgoing connections to arbitrary hosts from the compromised server, possibly leaking data or enabling further attacks within the internal network.

Generated by OpenCVE AI on July 31, 2026 at 11:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the bdthemes Instant Image Generator plugin to the latest version (if available, e.g., 2.1.5 or newer) to eliminate the vulnerability.
  • If a newer version is not yet available, restrict outbound HTTP traffic from the web server or WordPress application to a whitelist of trusted hosts to limit SSRF impact.
  • Configure the web server to reject HTTP requests containing potentially malicious URL components, and enable logging of all outbound requests from the image‑generation endpoint so that suspicious activity can be detected.

Generated by OpenCVE AI on July 31, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Bdthemes
Bdthemes instant Image Generator
Wordpress
Wordpress wordpress
Vendors & Products Bdthemes
Bdthemes instant Image Generator
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects Instant Image Generator: from n/a through <= 2.1.4.
Title WordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Bdthemes Instant Image Generator
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:49:41.734Z

Reserved: 2026-06-24T12:46:38.624Z

Link: CVE-2026-57413

cve-icon Vulnrichment

Updated: 2026-07-13T13:49:38.570Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)