
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49985 is a Server-Side Request Forgery (SSRF) vulnerability in the Auto Upload Images WordPress plugin developed by Ali Irani. It affects all versions from n/a through 3.3.2 (inclusive). The vulnerability was published on June 20, 2025, and carries a CVSS v3.1 base score of 4.9 (Medium) (Feedly, Wordfence).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and resides in the Auto Upload Images plugin's image-fetching functionality, which retrieves remote images and uploads them to the WordPress media library. An authenticated attacker with low privileges can supply a crafted URL that causes the server to make HTTP requests to arbitrary internal or external hosts, bypassing network perimeter controls. Exploitation requires high attack complexity and no user interaction, but the scope is changed — meaning the impact can extend beyond the vulnerable component itself (Feedly, Patchstack).
Successful exploitation allows an authenticated attacker to force the WordPress server to issue requests to internal network resources (e.g., cloud metadata endpoints, internal APIs, or services on localhost), resulting in limited confidentiality and integrity impacts (both rated Low). Availability is not impacted. The changed scope indicates potential for pivoting to internal infrastructure not directly accessible from the internet, such as AWS/GCP/Azure instance metadata services or internal administrative panels (Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.028%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a low-privilege authenticated account on the WordPress site and high attack complexity, limiting the attacker pool (Feedly, Wordfence).
/wp-content/plugins/auto-upload-images/).http://169.254.169.254/latest/meta-data/ for AWS metadata, or http://localhost:8080/admin).169.254.169.254, 10.0.0.0/8, 192.168.0.0/16, 127.0.0.1) originating from the web server process./wp-admin/admin-ajax.php or post-save actions) with suspicious url parameters containing internal addresses./wp-content/uploads/ that are not valid images (e.g., HTML or JSON content saved with image extensions), potentially containing cloud metadata or internal service responses.php-fpm, apache2) initiating outbound connections to non-standard internal hosts or metadata endpoints.Site administrators should update the Auto Upload Images plugin to a version beyond 3.3.2 once a patched release is available from the plugin author (Ali Irani). In the interim, consider deactivating or removing the plugin if remote image auto-upload functionality is not critical. Additionally, implement egress firewall rules on the WordPress server to block outbound requests to internal IP ranges and cloud metadata endpoints (e.g., 169.254.169.254). Restrict WordPress user roles to minimize the number of accounts with post-creation privileges (Patchstack, Wordfence).
Wordfence included CVE-2025-49985 in its weekly WordPress vulnerability report for the period of June 16–22, 2025, noting it as part of a broader set of plugin vulnerabilities disclosed that week. No significant independent researcher commentary or media coverage beyond standard vulnerability aggregation has been observed (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."