plugin

Media Cleaner Vulnerabilities

2 known security issues reported for the Media Cleaner WordPress plugin. Most recent disclosed Jul 27, 2026.

2 medium

Running Media Cleaner on your site? Check whether your installed version is affected.

Scan your site free

Media Cleaner: Clean your WordPress! <= 7.0.3 - Authenticated (Administrator+) Server-Side Request Forgery

medium

The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.3. This is due to the `get_urls_from_html()` function using `DOMDocument::loadHTMLFile()` to fetch iframe source URLs with an insufficient hostname validation check that r...

CVSS:
4.1
Affected:
up to 7.0.3
Fixed in:
7.0.6
Disclosed:
Jul 27, 2026

CVE-2026-4912 on NVD →

Media Cleaner: Clean your WordPress! <= 6.7.2 - Unauthenticated Information Exposure

medium

The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.2 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

CVSS:
5.3
Affected:
up to 6.7.2
Fixed in:
6.7.3
Disclosed:
Apr 29, 2024

CVE-2024-33922 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database