
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22482 is a Server-Side Request Forgery (SSRF) vulnerability in the IMGspider WordPress plugin developed by wbolt.com. It affects all versions of IMGspider through 2.3.12 and was disclosed on January 22, 2026, with the CVE assigned by Patchstack. The vulnerability carries a CVSS v3.1 base score of 4.9 (Medium), as assessed by Patchstack (NVD, Patchstack).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and resides in the IMGspider WordPress plugin, which is designed for image crawling and caching. An authenticated attacker with low privileges can craft malicious requests that cause the server to make outbound HTTP requests to arbitrary internal or external destinations. Exploitation requires high attack complexity and no user interaction, and the scope is changed, meaning the impact can extend beyond the vulnerable component itself (NVD, Patchstack).
Successful exploitation allows an attacker to make the vulnerable server issue requests to internal network resources, cloud metadata endpoints (e.g., AWS IMDSv1), or other internal APIs that would otherwise be inaccessible from the internet. This results in limited confidentiality and integrity impacts — an attacker may read sensitive internal data or interact with internal services. Availability is not directly impacted, but the ability to probe internal infrastructure could facilitate further lateral movement or privilege escalation (NVD).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term (NVD).
http://169.254.169.254/latest/meta-data/ for AWS metadata, or http://192.168.1.1/admin) as the image source parameter.Users should check with wbolt.com for an updated version of the IMGspider plugin that addresses this vulnerability and upgrade immediately if a patched version is available. As a temporary workaround, administrators should implement network-level egress filtering to restrict outbound connections from the WordPress server to internal network ranges and cloud metadata endpoints. Additionally, consider disabling the IMGspider plugin entirely if it is not critical to operations until a patch is confirmed (NVD, Patchstack).
The vulnerability was noted in Wordfence's weekly WordPress vulnerability report covering the period of January 5–11, 2026, indicating routine tracking by the WordPress security community. No significant vendor statements, researcher commentary, or broader media coverage has been identified beyond standard vulnerability database listings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."