Auto Upload Images

Auto Upload Images has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; 2 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.9, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2022 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Server-Side Request Forgery (SSRF).

2 of the records (67%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.

2 independent researchers contributed these findings, most of them (2) reported by Rasi Afeef. Auto Upload Images is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.9/ 10
Patch Coverage67%
Open

1

Fixed

2

Get automatic notifications for all Auto Upload Images vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2025-49985

Auto Upload Images <= 3.3.2 - Authenticated (Contributor+) Server-Side Request Forgery

Read the full analysis

Vulnerability Records

3 records
Auto Upload Images banner
Latestv3.4.0

Auto Upload Images

Ali Irani

Author

Ali Irani

4.3(106)
86/100
Last Updated
2026-09-13 (10h ago)
Active Installs
20,000+
Downloads
334,818
Requires WP
5.0+
Requires PHP
0+
Tested up to
WP 7.1
Created
2012-11-13 (14y ago)

When you want to save a post, this plugin search for image urls which exists in post and automatically upload and import external images to the WordPress upload directory and add images to the media library and then replace new image urls with old urls. Features Automatically find images in posts and save them to the your server and wp media library Update posts with new image urls in your server Add images saved by plugin to the WordPress media library Process image urls inside selected custom fields, in addition to the post content Select custom post types for excluding auto upload images Choose exclude domain to save images from this domain address Choose custom your base url for images Choose custom images file name with patterns Choose custom image alt name with patterns Choose max width and height for images uploaded Protect your site from SSRF attacks: private and reserved IP addresses, cloud metadata endpoints and non-HTTP protocols are blocked, redirects are re-validated Translators English Persian (fa_IR) – Ali Irani Español (es) – Diego Herrera Russian (ru_RU) – Артём Рябков German (de_DE) – Till Zimmermann French (fr_FR) – Malaiac Korean (ko_KR) – Shodan Italian (it_IT) – Patryk Chmura Links Official Plugin Page Github Repository Report Issues

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C