MimeTypes Link Icons WordPress Plugin Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in the MimeTypes Link Icons plugin for WordPress, affecting all versions through 3.2.20. The vulnerability arises because the plugin allows outbound HTTP requests to user-controlled URLs without adequate validation, particularly when the 'Show file size' option is activated. This flaw enables authenticated attackers with Contributor-level access or higher to send web requests to arbitrary locations from the web application. Exploitation could involve querying and modifying information from internal services using crafted links embedded in post content.

Impact

Exploitation of this vulnerability could lead to unauthorized web requests being made to internal services, potentially allowing attackers to access or modify sensitive information.

Reproduction

To reproduce this vulnerability, activate the MimeTypes Link Icons plugin and enable the 'Show file size' option. Then, create a post containing a link that points to an internal service or resource. When the post is published, the plugin will make an unvalidated HTTP request to the URL specified in the link, effectively exploiting the SSRF vulnerability.

Added: Mar 21, 2026, 4:51 AM
Updated: Mar 21, 2026, 4:51 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.3
remediation
0.0
relevance
4.2
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.