CVE-2025-12359 Overview
The Responsive Lightbox & Gallery plugin for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability [CWE-918] in all versions up to and including 2.5.3. The flaw resides in the get_image_size_by_url function, which fails to properly validate user-supplied URLs when determining image dimensions for gallery items. Authenticated attackers holding Author-level access or above can force the WordPress server to issue arbitrary HTTP requests. These requests originate from the vulnerable host and can reach internal services normally shielded from external networks. The issue affects a widely deployed gallery plugin, expanding the potential attack surface for lateral network reconnaissance.
Critical Impact
Authenticated attackers can pivot through the WordPress instance to query and modify internal-only services, including cloud metadata endpoints and unauthenticated intranet APIs.
Affected Products
- Responsive Lightbox & Gallery plugin for WordPress, versions ≤ 2.5.3
- WordPress installations exposing Author-level or higher accounts to untrusted users
- Sites running the vulnerable class-fast-image.php and class-frontend.php handlers
Discovery Timeline
- 2025-11-19 - CVE-2025-12359 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-12359
Vulnerability Analysis
The vulnerability sits in the get_image_size_by_url function defined in includes/functions.php, which is invoked from gallery-related handlers such as class-frontend.php and class-galleries.php. The function accepts a URL parameter intended to point at an image, then delegates to the Fast_Image class in class-fast-image.php to fetch remote content and read image dimensions. The plugin does not restrict the destination host, scheme, or IP range before issuing the outbound request. An authenticated Author-level user can therefore trigger requests to internal IP addresses, loopback interfaces, or cloud metadata services such as 169.254.169.254. Response data or error signals may leak information about the internal environment, and requests can also be directed at unauthenticated internal endpoints capable of state-changing operations.
Root Cause
The root cause is missing URL validation before performing server-side HTTP fetches. Neither the caller nor Fast_Image enforces an allowlist of trusted hosts, blocks private IP ranges (RFC 1918, link-local, loopback), or restricts schemes to http/https served from known image origins. This aligns with the classic SSRF pattern described in [CWE-918].
Attack Vector
Exploitation requires an authenticated session with Author privileges or higher. The attacker submits a crafted URL through gallery item creation or edit flows that eventually reach get_image_size_by_url. The vulnerable function issues an outbound request to the attacker-controlled destination, which may be an internal service address. The vulnerability is remotely reachable over the network with low complexity and no user interaction. Refer to the Wordfence CVE Vulnerability Analysis and the CleanTalk CVE-2025-12359 Report for additional technical context. No verified public exploit code is available at the time of writing.
Detection Methods for CVE-2025-12359
Indicators of Compromise
- Outbound HTTP requests from the WordPress PHP worker to private IP ranges such as 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, or 127.0.0.0/8.
- Requests from the WordPress host to cloud metadata endpoints, notably http://169.254.169.254/.
- Gallery item entries containing non-image URLs, unusual ports, or hostnames that do not match expected CDN or media origins.
Detection Strategies
- Monitor PHP-FPM or webserver process egress with a network sensor and alert on connections to internal RFC 1918 addresses.
- Enable WordPress audit logging for gallery create and update actions performed by Author-level accounts, correlating with subsequent server-side fetch events.
- Inspect webserver access logs for POST requests to admin-ajax.php and gallery REST endpoints that include URL parameters with non-standard hosts or ports.
Monitoring Recommendations
- Baseline expected outbound destinations for the WordPress host and alert on deviations from that allowlist.
- Track new or modified user accounts granted Author, Editor, or Administrator roles.
- Monitor cloud provider audit logs (AWS CloudTrail, Azure Activity Log, GCP Cloud Audit Logs) for unusual metadata service access from the WordPress workload identity.
How to Mitigate CVE-2025-12359
Immediate Actions Required
- Update the Responsive Lightbox & Gallery plugin to a version later than 2.5.3 that includes the fix referenced in the WordPress Responsive Lightbox Change Log.
- Audit all Author-level and above accounts, removing dormant or untrusted users to reduce the pool of accounts able to trigger the flaw.
- Rotate any secrets that could have been exposed via cloud metadata SSRF, including instance role credentials.
Patch Information
The vendor addressed the SSRF by modifying the affected files in the plugin trunk. The changeset replaces the trunk revision 3358021 with 3397940. Site owners should upgrade to the plugin release built from the patched trunk, verifiable in the change log linked above. Source references for the vulnerable code are documented in the WordPress Responsive Lightbox PHP File and WordPress Responsive Lightbox Functions PHP.
Workarounds
- Temporarily restrict Author-level or higher access to trusted staff only until the patched plugin release is deployed.
- Enforce egress filtering on the WordPress host to block outbound traffic to RFC 1918 ranges, loopback, and cloud metadata IP 169.254.169.254.
- On AWS instances, require IMDSv2 with hop limit of 1 to reduce the impact of SSRF against instance metadata.
# Configuration example: block SSRF-adjacent egress from PHP workers using iptables
iptables -A OUTPUT -m owner --uid-owner www-data -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 10.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 172.16.0.0/12 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 192.168.0.0/16 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 127.0.0.0/8 ! -o lo -j REJECT
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
