CVE-2026-12106 Overview
The Auto Upload Images plugin for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability [CWE-918] in all versions up to and including 3.3.2. The flaw resides in the downloadImage function, which uses wp_remote_get() instead of the safer wp_safe_remote_get(). The plugin's validate() method only rejects URLs whose host matches the site's own hostname, allowing requests to private, loopback, and link-local addresses. Authenticated attackers with contributor-level access can force the server to issue outbound HTTP requests to internal network hosts, including cloud metadata endpoints such as 169.254.169.254.
Critical Impact
Authenticated contributors can pivot to internal networks and potentially access cloud metadata services, enabling reconnaissance of otherwise unreachable infrastructure.
Affected Products
- WordPress Auto Upload Images plugin versions ≤ 3.3.2
- WordPress sites permitting contributor-level user registration
- Cloud-hosted WordPress deployments exposing metadata endpoints (AWS, Azure, GCP)
Discovery Timeline
- 2026-09-18 - CVE CVE-2026-12106 published to NVD
- 2026-09-18 - Last updated in NVD database
Technical Details for CVE-2026-12106
Vulnerability Analysis
The Auto Upload Images plugin automatically fetches remote images embedded in post content and stores them in the WordPress media library. When a post is submitted, the plugin parses <img> tags and dispatches an HTTP GET to each src URL through the downloadImage function. This behavior becomes exploitable because the plugin does not restrict target hosts beyond a same-host check.
By authoring a draft or post containing a crafted <img> tag pointing to an internal IP address, a contributor triggers the server to issue an outbound request on their behalf. The response body may be reflected back to the attacker as image content or surface through error handling, enabling data exfiltration from internal services. On cloud-hosted instances, this can expose instance metadata, temporary IAM credentials, and internal orchestration APIs.
Root Cause
Two compounding weaknesses cause the vulnerability. First, the plugin calls wp_remote_get() rather than wp_safe_remote_get(), bypassing WordPress core's built-in host filtering that blocks private and loopback ranges. Second, the validate() method in ImageUploader.php only compares the target host against the site's own hostname, leaving 127.0.0.1, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, and 169.254.0.0/16 reachable.
Attack Vector
Exploitation requires an authenticated account with contributor privileges or higher. The attacker submits post content containing an <img> element whose src attribute references an internal resource such as http://169.254.169.254/latest/meta-data/ or http://127.0.0.1:8080/admin. When the plugin processes the post, the WordPress server issues the request from its own network position, bypassing perimeter firewalls.
Refer to the WordPress Image Uploader Source and the Wordfence Vulnerability Report for technical details.
Detection Methods for CVE-2026-12106
Indicators of Compromise
- Outbound HTTP requests from the WordPress web server to RFC1918 addresses, 127.0.0.1, or 169.254.169.254
- Post revisions authored by contributor accounts containing <img> tags with private-IP or loopback src attributes
- Unexpected entries in the WordPress media library referencing internal hostnames
- Cloud metadata service access logs originating from the WordPress host during post submission events
Detection Strategies
- Inspect web server egress logs for connections to internal subnets initiated by the PHP worker process
- Review the wp_posts table for draft or pending content containing src="http://10.", src="http://192.168.", src="http://127.", or src="http://169.254." patterns
- Correlate contributor account activity with atypical outbound network flows from the web tier
Monitoring Recommendations
- Enable cloud provider metadata service auditing (IMDSv2 with session tokens on AWS) and alert on unauthorized access attempts
- Monitor the auto-upload-images plugin log output and PHP error logs for failed remote fetch attempts targeting internal hosts
- Track newly registered contributor accounts followed by rapid post submission activity
How to Mitigate CVE-2026-12106
Immediate Actions Required
- Update the Auto Upload Images plugin to a version above 3.3.2 once the patched release is available
- Restrict contributor-level and higher account creation, and audit existing low-privilege accounts for suspicious activity
- Enforce IMDSv2 on AWS EC2 instances hosting WordPress to require session-token authentication for metadata access
- Deploy egress network controls that block the WordPress web tier from reaching private and link-local ranges
Patch Information
The vendor addressed the issue in the plugin repository. Review the WordPress Plugin Changeset for the corrective commit. Site administrators should apply the update through the WordPress plugins dashboard or via WP-CLI.
Workarounds
- Deactivate the Auto Upload Images plugin until the patched version is deployed
- Apply a WAF rule that inspects post submissions for <img> tags with private-IP or loopback src values and blocks the request
- Configure the WordPress host firewall to deny outbound traffic to 127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, and 169.254.0.0/16
- Downgrade contributor accounts to subscriber level where publishing is not required
# Example egress restriction using iptables on the WordPress host
iptables -A OUTPUT -m owner --uid-owner www-data -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 127.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 10.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 172.16.0.0/12 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 192.168.0.0/16 -j REJECT
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
