What is CVE-2026-24639?
CVE-2026-24639 is an Author-level Server Side Request Forgery (SSRF) vulnerability in Photo Block plugin versions <= 1.7.1. It allows authenticated low-privileged users (authors) to make unintended server-side requests. To mitigate, update the plugin to the latest version.
Azərbaycanca: CVE-2026-24639, Photo Block plagininin 1.7.1 və aşağı versiyalarında müəllif səviyyəli Server Side Request Forgery (SSRF) zəifliyidir. Bu zəiflik autentifikasiya olunmuş aşağı səviyyəli istifadəçilərə (müəllif) server daxilində arzuolunmaz sorğular göndərməyə imkan verir. Təsirə məruz qalmamaq üçün plagin ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What level of user privilege is required to exploit CVE-2026-24639?
This SSRF vulnerability requires an authenticated low-privileged user with Author-level access.
To which version should the Photo Block plugin be updated to mitigate CVE-2026-24639?
The Photo Block plugin should be updated to the latest version above 1.7.1 to avoid being affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.