PLUGIN SECURITY
Is Instant Images safe?
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
What this plugin does
- Slug:
instant-images - Author: connekthq
- 100000+ active installs
- 96/100 rating (59 reviews on wordpress.org)
- 3218460 all-time downloads
- On WordPress.org since 2016-11-01
free imagesmedia librarypixabaystock photosunsplash
Maintenance status
- Latest known version: 7.2.0
- Last updated: 2026-06-01 6:11pm GMT
- Tested up to WordPress: 7.0.4
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
4 known CVEs on file for Instant Images. Reported between 2021 and 2024.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-33569 | Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy [instant-images] < 6.1.1 | Improper Privilege Management | High 7.2 | < 6.1.1 | 6.1.1 | 2024-04-25 | ✓ fixed in latest |
| CVE-2024-0869 | Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy [instant-images] < 6.1.1 | Missing Authorization | Medium 6.5 | < 6.1.1 | 6.1.1 | 2024-01-29 | ✓ fixed in latest |
| CVE-2023-27451 | Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy [instant-images] < 5.2.0 | Server-Side Request Forgery (SSRF) | High 7.2 | < 5.2.0 | 5.2.0 | 2023-03-02 | ✓ fixed in latest |
| CVE-2021-24334 | Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy [instant-images] < 4.4.0.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 4.4.0.1 | 4.4.0.1 | 2021-04-22 | ✓ fixed in latest |
| CVE-2024-0869 | Instant Images < 6.1.1 - Author+ Arbitrary Options Update | — | Unknown | < 6.1.1 | 6.1.1 | — | ✓ fixed in latest |
How to fix it
Keep Instant Images updated — 7.2.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager — 90000+ active installs — 100/100 (1517) — max PHP 8.4
- Media Library Assistant — 70000+ active installs — 96/100 (201) — max PHP 8.4
- Enhanced Media Library — 60000+ active installs — 86/100 (298) — max PHP 8.4
- Quick Featured Images — 50000+ active installs — 94/100 (235) — max PHP 8.4
- Crop-Thumbnails — 40000+ active installs — 92/100 (67)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.