Junglewise Threat Intelligence

CVE-2026-24639: Ronald Huereca Photo Block SSRF in WordPress plugin

CVE-2026-24639 · Severity: medium · CVSS 4.4 · Published 2026-07-23

Executive brief

Photo Block is a WordPress plugin used to display and manage images within the Gutenberg editor. A security vulnerability exists that allows a user with 'Author' level permissions to force the website to make unauthorized requests to other internal or external servers. This could be used to scan internal networks or access sensitive information from other services running on the same infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Photo Block plugin for WordPress (versions <= 1.7.1). The flaw allows an authenticated attacker with 'Author' privileges to submit crafted requests that the server then executes. This occurs because the plugin does not sufficiently validate user-supplied URLs before making server-side requests. An attacker can leverage this to probe internal network services or interact with external domains, potentially leading to information disclosure of internal metadata or services. As of the advisory date, no official patch has been released.

Affected products

  • Ronald Huereca (DLX Plugins) Photo Block <= 1.7.1

Timeline

  • 2025-12-05: other: Vulnerability reported by researcher Arif Shaikh
  • 2026-07-22: advisory: Advisory published by Patchstack
  • 2026-07-23: disclosed: CVE published in NVD dataset

References