Cache Images

Cache Images has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2022; all 2 are fixed as of September 2026. Their average CVSS score is 7.1, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2022 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for Cache Images has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Daniel Ruf. Cache Images is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.

Strategic Overview

Avg CVSSHigh
7.1/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Cache Images vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2022-2091

Cache Images <= 3.2 - Cross-Site Request Forgery to Image Upload

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv3.2.2
4.0(6)
80/100
Last Updated
2023-10-25 (3y ago)
Active Installs
1,000+
Downloads
53,178
Requires WP
2.8+
Requires PHP
0+
Tested up to
WP 6.4.10
Created
2005-02-08 (22y ago)

Plugin homepage | Plugin author Cache Images is a plugin that gives users option to sideload images that are hosted on other domains to their own site. Sideloaded images are added to WordPress media library so you can use all tools related to images that you can use with images uploaded through WordPress. Image will be added as an attachment of first post where it is found, and every post where original URL is occurring will be updated with new URL. User can select from which domains to sideload images, including Blogger’s domains. It uses AJAX so it means you can sideload large number of images even on slow servers. (AJAX functions are made by fork of code from plugin AJAX Thumbnail Rebuild) This plugin is fully internationalized. You can find .pot file in languages folder where you should place your translation. Current translations are Serbian, Spanish, and Persian. Please send your translation by contacting author so that it can be included it in next releases. Read more information about usage on author’s site.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C