CVE-2026-1356
Last modified
CVE-2026-1356 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.5.1 via the PassthruLoader::load_image_source function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.5.1 via the PassthruLoader::load_image_source function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-1356?
How severe is CVE-2026-1356?
How do I fix CVE-2026-1356?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13554A vulnerability has been found in itsourcecode Online Hotel …4.3
- CVE-2026-13555A vulnerability was found in itsourcecode Online Hotel Manag…7.3
- CVE-2026-13556A vulnerability was determined in itsourcecode Online Hotel …4.3
- CVE-2026-13557A vulnerability was identified in itsourcecode Online Hotel …4.3
- CVE-2026-13558A security flaw has been discovered in CodeAstro Complaint M…3.5
- CVE-2026-13559A weakness has been identified in code-projects Real State S…7.3
- CVE-2026-13560A security vulnerability has been detected in Edimax EW-7478…6.3
- CVE-2026-13561A vulnerability was detected in Edimax EW-7478APC 1.04. The …6.3
- CVE-2026-13562A flaw has been found in Edimax EW-7478APC 1.04. This affect…8.8
- CVE-2026-13563A vulnerability has been found in Edimax EW-7478APC 1.04. Th…8.8
- CVE-2026-13564A vulnerability was found in Edimax EW-7478APC 1.04. Affecte…8.8
- CVE-2026-13565A vulnerability was determined in SourceCodester Class and E…7.3
Are you affected by CVE-2026-1356?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
