Auto Save Remote Images (Drafts) WordPress Plugin Server-Side Request Forgery Vulnerability

Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Auto Save Remote Images (Drafts) WordPress plugin, affecting all versions through 1.0.9. The vulnerability arises in the fetch_images() function, allowing authenticated attackers with Contributor-level access and above to make web requests to arbitrary locations. This could be exploited to query and modify information from internal services.

Impact

Exploitation of this vulnerability could allow authenticated attackers to make unauthorized web requests from the application, potentially accessing or altering information from internal services.

Remediation

No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: Sep 10, 2025, 7:31 AM
Updated: Sep 10, 2025, 7:31 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.2
remediation
0.0
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.