VYPR

All In One Image Viewer Block

by WordPress

CVEs (1)

  • CVE-2026-1294HigFeb 5, 2026
    risk 0.40cvss 7.2epss 0.00

    The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the image-proxy REST API endpoint. This makes it possible for unauthenticated…