Instant AI Image Generator – Create & Import Images
Instant AI Image Generator – Create & Import Images has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Server-Side Request Forgery (SSRF), behind 1 of the records (50%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.
Every one of the 2 issues recorded for Instant AI Image Generator – Create & Import Images has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Instant AI Image Generator – Create & Import Images is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-52377Instant Image Generator <= 1.5.2 - Unauthenticated Arbitrary File Upload
Read the full analysisVulnerability Records

Instant AI Image Generator – Create & Import Images
Author
bdthemes
Instant AI Image Generator is the most powerful and complete image management plugin for WordPress. Stop wasting time searching for images across multiple websites, downloading them to your computer, and re-uploading to WordPress. With Instant AI Image Generator, you can search, preview, and import millions of free images directly into your WordPress Media Library — all without ever leaving your dashboard. 🔍 Search across 6+ image sources including Pixabay, Pexels, Wikimedia, Unsplash, Openverse, and Giphy — all from a single, unified search bar. Or use the AI-powered image generation with OpenAI GPT Image and Google Gemini Imagen to create completely unique images from text descriptions. USEFUL LINKS 👇 Documentation | Need Support? 🚀 Why Instant AI Image Generator? Finding the right image for your blog post, page, or product shouldn’t be a chore. Traditional workflows require you to open a new tab, search a stock photo website, download the image, switch back to WordPress, upload it, and then insert it. That’s 6 steps for a single image. With Instant AI Image Generator, it’s just 2 steps: Search → Import. Done. Whether you’re a blogger crafting your next viral post, an agency building client websites, a WooCommerce store owner adding product images, or a content creator who needs fresh visuals daily — this plugin transforms your workflow and saves you hours every week. Instant AI Image Generator integrates seamlessly into both the WordPress Media Library page and the WordPress Media Modal (the popup that appears when you click “Add Media” or set a Featured Image). This means you can access millions of images from anywhere in WordPress — while editing a post, creating a page, or managing your media. ✨ Key Features 🔍 Global Search — One Search, All Sources Search across all enabled image providers simultaneously with the Global Search tab. Type your keyword once, and instantly see results from Pixabay, Pexels, Unsplash, Openverse, and Giphy combined in a beautiful masonry grid. No more switching between tabs — find the perfect image faster than ever. 📸 5+ Free Image Sources Access millions of royalty-free, high-quality images from the world’s best stock photo libraries: 🟣 Pexels — Beautiful free stock photos curated by talented creators 🟢 Pixabay — Over 4.2 million free stock photos, illustrations, and vectors ⬛ Unsplash — The internet’s source for freely-usable high-resolution photos 🟠 Openverse — Open-licensed images from WordPress, Flickr, NASA, Wikimedia, and 10+ more sources 🎬 Giphy — The world’s largest library of animated GIFs with smart animation control 🤖 AI Image Generation Create completely unique, one-of-a-kind images using artificial intelligence: OpenAI GPT Image — Generate stunning AI images from text prompts using OpenAI’s latest image generation model Google Gemini Imagen 4.0 — Create photorealistic images with Google’s Imagen 4.0 model with customizable size (512px to 2048px) and batch generation (1-4 images) ⬇️ One-Click Import to Media Library Import any image straight to your WordPress Media Library with a single click — no downloading, no re-uploading, no FTP. 🖼️ WordPress Media Modal Integration An “Instant Images” tab appears in the WordPress media popup, right beside “Upload Files” and “Media Library”, so you can search and import while setting a Featured Image or adding media to a post. 🏷️ Smart Image Metadata On import the plugin can set Alternative Text, Image Title, and a Caption with attribution (“Photo by [Author Name]”). Each field has its own toggle in General Settings. 🎛️ Advanced Filtering Provider-specific filters: Pixabay (order, type, 20+ categories, 14 colors, orientation), Openverse (source, orientation), Unsplash (order), Pexels (curated collections), Wikimedia (media type, sort) and Giphy (trending). 🎬 GIF Animation Control Giphy GIFs load as still thumbnails to save bandwidth and animate on hover. A “GIF” badge marks animated results; the preview modal always plays them full size. 📋 Batch Selection & Import Select multiple images across any provider and import them all in one operation with a progress indicator. ❤️ Favorites & 🔍 Search History Bookmark images to a dedicated Favorites tab, and re-run recent searches from keyboard-navigable suggestions in the search bar. 👁️ Full-Size Image Preview Click any image for a large preview with author info, previous/next keyboard navigation, multiple import sizes, a Favorites button and a link to the original source. ⚙️ Comprehensive Dashboard Settings General — max upload width/height, default provider, Alt Text / Title / Attribution toggles, Media Modal visibility Display — view mode, items per page (20-100), thumbnail size, auto-scroll or manual “Load More” Image Sources — enable/disable each provider, drag-and-drop ordering that carries over to the Image Generator tabs, Global Search toggle Custom Image Sizes — review every registered WordPress size and add or delete your own (WordPress defaults are protected) Export & Import — back up or migrate your configuration as a JSON file 🎨 Modern UI, Lightweight Footprint Built with React and Tailwind CSS: card-based layouts, color-coded provider tabs, masonry grids and skeleton loading states. API requests are nonce-protected, keys are stored in WordPress options, there is no tracking or analytics, and assets load only on the admin screens that need them — zero frontend code on your public site. 🏆 Perfect For 📝 Bloggers — Find the perfect header image in seconds 🏢 Agencies — Build client websites faster with instant image access 🛒 WooCommerce Stores — Add product images without leaving WordPress 📰 News & Magazine Sites — Source images for articles quickly 🎨 Designers — AI-generate unique visuals from text descriptions 📱 Social Media Managers — Find trending GIFs and images instantly 👨💻 Developers — Add placeholder images during development External services This plugin is a client for third-party image services. It does not work without them: every image you search, generate or import is fetched from one of the services listed below. All of this happens inside wp-admin only — nothing is requested from your public-facing site, and no visitor data is collected or transmitted. Requests are made only when you actively use a feature: typing a search term, opening a provider tab, running Global Search, generating an AI image, using the block toolbar “Generate Image” action, importing an image, or clicking “Test key” in the settings. Each request carries the search term or prompt you typed and the API key for that provider. No WordPress user data, post content, site URL, or personal information is sent. Most providers are contacted by your own server through the WordPress HTTP API, so the provider sees your server’s IP address. Two are contacted directly by your browser instead, so the provider sees the IP address of the computer you are working on: Openverse search, and OpenAI image generation from the Image Generator page. Preview thumbnails are also loaded straight into your browser from each provider’s image CDN, as with any image on a web page. Pexels, Pixabay, Unsplash and Giphy ship with a shared BdThemes API key so they work without configuration. That means the plugin can contact those four services before you enter any key of your own. Disable a provider in AI Image → Dashboard → Image Sources to stop the plugin from contacting it. Pixabay Used to search and import Pixabay stock photos, illustrations and vectors. Your search term, filter values (order, type, category, color, orientation), page number and the Pixabay API key are sent to https://pixabay.com/api/ each time you search the Pixabay tab or Global Search. Terms of Service: https://pixabay.com/service/terms/ | Privacy Policy: https://pixabay.com/service/privacy/ Pexels Used to search and import Pexels stock photos. Your search term, page number and the Pexels API key are sent to https://api.pexels.com/ each time you search the Pexels tab, Global Search, or use the block toolbar image action. Terms of Service: https://www.pexels.com/terms-of-service/ | Privacy Policy: https://www.pexels.com/privacy-policy/ Unsplash Used to search and import Unsplash photos. Your search term, page number and the Unsplash Access Key are sent to https://api.unsplash.com/ when you search the Unsplash tab or Global Search, and when you validate an Unsplash key in the dashboard. Terms of Service: https://unsplash.com/terms | Privacy Policy: https://unsplash.com/privacy Openverse (WordPress.org) Used to search and import openly licensed images. Your search term, source/orientation filters and page number are sent to https://api.openverse.org/v1/ directly from your browser when you search the Openverse tab or Global Search, and to https://api.openverse.engineering/ from your server when you use the block toolbar “Generate Image” action. No API key is required. Terms of Service: https://docs.openverse.org/terms_of_service.html | Privacy Policy: https://openverse.org/privacy Wikimedia Commons Used to search and import freely licensed media from Wikimedia Commons. Your search term, media type/sort filters and page number are sent to https://commons.wikimedia.org/w/api.php when you search the Wikimedia tab or Global Search. No API key is required. Terms of Use: https://foundation.wikimedia.org/wiki/Policy:Terms_of_Use | Privacy Policy: https://foundation.wikimedia.org/wiki/Policy:Privacy_policy GIPHY Used to search, browse trending, and import animated GIFs. Your search term, page number and the GIPHY API key are sent to https://api.giphy.com/ when you search or open the Giphy tab, use Global Search, and when you validate a GIPHY key in the dashboard. Terms of Service: https://support.giphy.com/hc/en-us/articles/360020027752-GIPHY-User-Terms-of-Service | Privacy Policy: https://support.giphy.com/hc/en-us/articles/360032872931-GIPHY-Privacy-Policy OpenAI (GPT Image) Used to generate AI images from text. The text prompt you type, the requested image size/quality and your own OpenAI API key are sent to https://api.openai.com/v1/images/generations when you press Generate on the OpenAI tab (sent directly from your browser) or use the block toolbar “Generate Image” action with OpenAI (sent from your server). Your API key is also sent to https://api.openai.com/v1/models when you click “Test key”. This service requires your own API key and is used only after you add one. Terms of Use: https://openai.com/policies/terms-of-use/ | Privacy Policy: https://openai.com/policies/privacy-policy/ Google Gemini (Imagen) Used to generate AI images from text. The text prompt you type, the image size and image count, and your own Google Gemini API key are sent to https://generativelanguage.googleapis.com/v1beta/models/imagen-4.0-generate-001:predict when you press Generate on the Gemini tab or use the block toolbar “Generate Image” action with Gemini. Your API key is also sent to https://generativelanguage.googleapis.com/v1beta/models when you click “Test key”. This service requires your own API key and is used only after you add one. Terms of Service: https://ai.google.dev/gemini-api/terms | Privacy Policy: https://policies.google.com/privacy That is the complete list. Fallback author avatars, shown when a provider returns a photographer without a profile picture, are drawn in your browser as a local SVG — no avatar service is contacted. Source code The plugin ships with a compiled React/Tailwind bundle in build/. The complete, uncompressed human-readable source for that bundle is included in this plugin under the src/ directory, along with the build configuration (package.json, gruntfile.js, tailwind.config.js, postcss.config.js). The bundle is built with @wordpress/scripts (webpack + Babel), Tailwind CSS and Grunt. To rebuild it from source: Install Node.js 16 or later and npm. From the plugin directory, install dependencies: npm install Produce the production bundle: npm run build npm run build compiles src/admin/index.js and the Tailwind stylesheets into build/admin/index.js and build/admin/index.css, copies static assets into assets/, and regenerates the translation template. Use npm start for an unminified development build with file watching. No other third-party library in this plugin is minified or obfuscated. Checkout our other Plugins 👑 More free Elementor and Gutenberg addons from BdThemes: Element Pack (300+ Elementor widgets), Prime Slider (slider builder), Ultimate Post Kit (blogging layouts), Ultimate Store Kit (WooCommerce and EDD), Pixel Gallery (gallery widgets), ZoloBlocks (Gutenberg blocks), Augmented Reality Viewer, Dark Reader, Live Copy Paste, One Accessibility, QR Code Generator & Scanner, Smart Admin Assistant, Spin Wheel and Swift Checkout for WooCommerce. Visit BdThemes for our services, products, blogs and documentation.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C