Junglewise Threat Intelligence

CVE-2026-57413: bdthemes Instant Image Generator SSRF in ai-image

CVE-2026-57413 · Severity: medium · CVSS 6.4 · Published 2026-07-13

Vendors: BdThemes.

Executive brief

The Instant Image Generator plugin for WordPress, which uses AI to create images, contains a security flaw that allows authenticated users to make the server perform unauthorized web requests. An attacker could use this to probe internal network services or access sensitive information that is not intended to be public. This could lead to internal data exposure or be used as a stepping stone for further attacks on the organization's infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the 'ai-image' component of the bdthemes Instant Image Generator plugin for WordPress. The flaw is present in versions up to and including 2.1.4. The vulnerability is classified as CWE-918 and allows an attacker with at least 'Subscriber' level privileges to force the server to make requests to arbitrary external or internal URLs. This can be exploited to bypass firewalls, scan internal networks, or interact with internal services that are otherwise inaccessible from the public internet. The issue is addressed in version 2.1.5.

Affected products

  • bdthemes Instant Image Generator (ai-image) <= 2.1.4

Timeline

  • 2026-05-12: other: Vulnerability reported by ParkHyunWoo
  • 2026-07-08: advisory: Patchstack published advisory
  • 2026-07-13: disclosed: CVE published to NVD
  • 2026-07-13: patched: Patch available in version 2.1.5

References