CVE · Medium

CVE-2026-4912 — Media Cleaner: Clean your WordPress! [media-cleaner] < 7.0.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-4912 Media Cleaner: Clean your WordPress! [media-cleaner] < 7.0.6 Server-Side Request Forgery (SSRF) Medium 4.1 < 7.0.6 7.0.6 2026-07-27

CVE-2026-4912

The Media Cleaner: Clean your WordPress! plugin contains a flaw in its handling of iframe source URLs that allows an attacker with elevated privileges to bypass hostname validation checks. This vulnerability enables the exploitation of Server-Side Request Forgery by using the `get_urls_from_html()` function, which fetches URLs without properly verifying their origin. As a result, attackers can initiate unauthorized web requests from within the application itself.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.