All In One Image Viewer Block <= 1.0.2 - Unauthenticated Server-Side Request Forgery via image-proxy Endpoint
highThe All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the image-proxy REST API endpoint. This makes it possible for unauthenticated attackers to make web requests to arbitrary loc...
- CVSS:
- 7.2
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.3
- Disclosed:
- Feb 4, 2026