What is CVE-2026-4912?
The 'Media Cleaner: Clean your WordPress!' plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to 7.0.3. This flaw exists in the `get_urls_from_html()` function, which uses `DOMDocument::loadHTMLFile()` to fetch iframe source URLs with insufficient hostname validation. Users are advised to update the plugin to the latest version.
Azərbaycanca: WordPress üçün 'Media Cleaner: Clean your WordPress!' plugininin 7.0.3 versiyasına qədər olan bütün versiyalarında Server-Side Request Forgery (SSRF) zəifliyi aşkar edilib. Bu zəiflik `get_urls_from_html()` funksiyasının iframe mənbə URL-lərini əldə edərkən yetərsiz host adı yoxlaması səbəbindən yaranır. İstifadəçilərə plagini ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of the 'Media Cleaner' plugin for WordPress are affected by CVE-2026-4912?
The vulnerability affects all versions of the 'Media Cleaner: Clean your WordPress!' plugin up to version 7.0.3.
What causes the CVE-2026-4912 vulnerability?
The vulnerability is caused by insufficient hostname validation in the `get_urls_from_html()` function when fetching iframe source URLs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.