Media Cleaner: Clean your WordPress! <= 7.0.3 - Authenticated (Administrator+) Server-Side Request Forgery
medium
The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.3. This is due to the `get_urls_from_html()` function using `DOMDocument::loadHTMLFile()` to fetch iframe source URLs with an insufficient hostname validation check that r...
- CVSS:
- 4.1
- Affected:
- up to 7.0.3
- Fixed in:
- 7.0.6
- Disclosed:
- Jul 27, 2026
CVE-2026-4912 on NVD →
Media Cleaner: Clean your WordPress! <= 6.7.2 - Unauthenticated Information Exposure
medium
The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.2 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.
- CVSS:
- 5.3
- Affected:
- up to 6.7.2
- Fixed in:
- 6.7.3
- Disclosed:
- Apr 29, 2024
CVE-2024-33922 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database