CVE-2026-1294

HIGH

All In One Image Viewer Block <1.0.2 - SSRF

Title source: llm
STIX 2.1

Description

The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the image-proxy REST API endpoint. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Scores

CVSS v3 7.2
EPSS 0.0029
EPSS Percentile 20.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
bplugins/All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink < 1.0.2
Published Feb 05, 2026
Tracked Since Feb 18, 2026