Junglewise Threat Intelligence

CVE-2026-39630: Getty Images WordPress Plugin SSRF

CVE-2026-39630 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Executive brief

A security vulnerability exists in the Getty Images plugin for WordPress, which allows users to easily embed professional imagery into their websites. An attacker with basic contributor-level access can trick the website's server into making unauthorized requests to internal or external systems. This could lead to the exposure of sensitive internal data or allow the attacker to probe other services running within the organization's private network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Getty Images WordPress plugin (versions <= 4.1.0). The flaw allows an authenticated attacker with 'Contributor' or higher privileges to induce the server to make requests to arbitrary domains. This is classified as CWE-918 and can be used to bypass network firewalls to access internal services or perform port scanning of the local network. As of the advisory date, no official patch has been released by the vendor. The vulnerability was assigned a CVSS v3.1 score of 6.4, reflecting that while it requires authentication, it can lead to a change in scope (S:C) by impacting resources beyond the plugin itself.

Affected products

  • Getty Images Getty Images <= 4.1.0

Timeline

  • 2026-01-14: other: Vulnerability reported by researcher Nabil Irawan
  • 2026-02-13: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References