📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global data_breach Government HIGH 1h Global malware Software Development CRITICAL 1h Global phishing Multiple Sectors HIGH 1h Global vulnerability Web Applications CRITICAL 2h Global apt Critical Infrastructure CRITICAL 2h Global ransomware Multiple sectors CRITICAL 2h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 3h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 4h Global general Consumer Electronics and Retail MEDIUM 6h Global supply_chain Software Development and Technology HIGH 6h Global data_breach Government HIGH 1h Global malware Software Development CRITICAL 1h Global phishing Multiple Sectors HIGH 1h Global vulnerability Web Applications CRITICAL 2h Global apt Critical Infrastructure CRITICAL 2h Global ransomware Multiple sectors CRITICAL 2h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 3h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 4h Global general Consumer Electronics and Retail MEDIUM 6h Global supply_chain Software Development and Technology HIGH 6h Global data_breach Government HIGH 1h Global malware Software Development CRITICAL 1h Global phishing Multiple Sectors HIGH 1h Global vulnerability Web Applications CRITICAL 2h Global apt Critical Infrastructure CRITICAL 2h Global ransomware Multiple sectors CRITICAL 2h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 3h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 4h Global general Consumer Electronics and Retail MEDIUM 6h Global supply_chain Software Development and Technology HIGH 6h
Vulnerabilities

CVE-2026-1294

High
The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the i
CWE-918 — Weakness Type
Published: Feb 5, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
7.2
🔗 NVD Official
📄 Description (English)

The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the image-proxy REST API endpoint. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

🤖 AI Executive Summary

The All In One Image Viewer Block WordPress plugin (versions ≤1.0.2) contains a critical Server-Side Request Forgery (SSRF) vulnerability in its REST API endpoint that allows unauthenticated attackers to make arbitrary web requests from the affected server. This vulnerability enables attackers to access internal services, query sensitive data, and potentially modify information without authentication. The lack of URL validation and authorization controls makes this a high-risk vulnerability requiring immediate patching across all affected WordPress installations.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 9, 2026 03:34
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations using WordPress with the All In One Image Viewer Block plugin face significant risk, particularly in the banking sector (SAMA-regulated institutions), government agencies (NCA oversight), healthcare providers, and e-commerce platforms. The SSRF vulnerability could enable attackers to access internal banking systems, government databases, healthcare records, and payment processing systems. Energy sector organizations (ARAMCO, utilities) and telecommunications providers (STC, Mobily) running WordPress-based portals are also at risk. The vulnerability's unauthenticated nature makes it particularly dangerous for organizations with internet-facing WordPress installations, potentially allowing lateral movement to internal networks and access to sensitive data stored on internal services.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Healthcare and Medical Services Energy and Utilities Telecommunications E-commerce and Retail Education Insurance
⚖️ Saudi Risk Score (AI)
8.1
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all WordPress installations using the All In One Image Viewer Block plugin by checking wp-content/plugins/ directory and WordPress admin dashboard
2. Disable the plugin immediately if patch is not yet available: wp-cli plugin deactivate all-in-one-image-viewer-block
3. Review web server logs (access.log, error.log) for suspicious requests to /wp-json/image-proxy endpoints dating back 30 days
4. Check for indicators of compromise: unusual outbound connections, modified internal service data, unauthorized API calls

PATCHING GUIDANCE:
1. Update the All In One Image Viewer Block plugin to version 1.0.3 or later immediately
2. Use WordPress admin dashboard: Plugins > All In One Image Viewer Block > Update, or via wp-cli: wp plugin update all-in-one-image-viewer-block
3. Test functionality in staging environment before production deployment
4. Verify plugin update completion and version number

COMPENSATING CONTROLS (if immediate patching not possible):
1. Implement Web Application Firewall (WAF) rules to block requests to /wp-json/image-proxy endpoints
2. Restrict REST API access via .htaccess or nginx configuration to authenticated users only
3. Implement IP whitelisting for REST API endpoints if possible
4. Disable REST API entirely if not required: add define('REST_API_ENABLED', false) to wp-config.php
5. Use security plugins (Wordfence, Sucuri) to monitor and block suspicious REST API activity

DETECTION RULES:
1. Monitor for POST/GET requests to /wp-json/image-proxy with unusual URL parameters
2. Alert on requests containing internal IP addresses (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) in request parameters
3. Track outbound connections from WordPress process to non-whitelisted internal services
4. Monitor for 200 responses from /wp-json/image-proxy endpoints to unauthenticated requests
5. Implement SIEM rules to detect multiple failed attempts to access internal services via the proxy endpoint
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع تثبيتات WordPress التي تستخدم مكون All In One Image Viewer Block بالتحقق من مجلد wp-content/plugins/ ولوحة تحكم WordPress
2. تعطيل المكون فورًا إذا لم يكن التصحيح متاحًا: wp-cli plugin deactivate all-in-one-image-viewer-block
3. مراجعة سجلات خادم الويب (access.log, error.log) للطلبات المريبة إلى نقاط نهاية /wp-json/image-proxy لمدة 30 يومًا الماضية
4. التحقق من مؤشرات الاختراق: اتصالات صادرة غير عادية، بيانات الخدمة الداخلية المعدلة، استدعاءات API غير مصرح بها

إرشادات التصحيح:
1. تحديث مكون All In One Image Viewer Block إلى الإصدار 1.0.3 أو أحدث فورًا
2. استخدام لوحة تحكم WordPress: Plugins > All In One Image Viewer Block > Update، أو عبر wp-cli: wp plugin update all-in-one-image-viewer-block
3. اختبار الوظيفة في بيئة التجميع قبل نشر الإنتاج
4. التحقق من اكتمال تحديث المكون ورقم الإصدار

الضوابط البديلة (إذا لم يكن التصحيح الفوري ممكنًا):
1. تنفيذ قواعد جدار حماية تطبيقات الويب (WAF) لحظر الطلبات إلى نقاط نهاية /wp-json/image-proxy
2. تقييد وصول REST API عبر ملف .htaccess أو إعدادات nginx للمستخدمين المصرح لهم فقط
3. تنفيذ القائمة البيضاء للعناوين IP لنقاط نهاية REST API إن أمكن
4. تعطيل REST API بالكامل إذا لم تكن مطلوبة: أضف define('REST_API_ENABLED', false) إلى wp-config.php
5. استخدام مكونات الأمان (Wordfence, Sucuri) لمراقبة وحظر نشاط REST API المريب

قواعد الكشف:
1. مراقبة طلبات POST/GET إلى /wp-json/image-proxy بمعاملات عنوان URL غير عادية
2. التنبيه على الطلبات التي تحتوي على عناوين IP داخلية (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) في معاملات الطلب
3. تتبع الاتصالات الصادرة من عملية WordPress إلى الخدمات الداخلية غير المدرجة في القائمة البيضاء
4. مراقبة استجابات 200 من نقاط نهاية /wp-json/image-proxy للطلبات غير المصرح بها
5. تنفيذ قواعد SIEM للكشف عن محاولات متعددة للوصول إلى الخدمات الداخلية عبر نقطة نهاية الوكيل
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.14.2.1 - Information security requirements for supplier relationships ECC 2024 A.13.1.3 - Segregation of networks ECC 2024 A.14.2.5 - Addressing information security in supplier agreements ECC 2024 A.13.2.1 - Access control to networks and network services
🔵 SAMA CSF
SAMA CSF 2.1 - Governance and Risk Management SAMA CSF 3.2 - Access Control and Authentication SAMA CSF 3.3 - Data Protection and Privacy SAMA CSF 4.1 - Vulnerability Management SAMA CSF 4.2 - Patch Management
🟡 ISO 27001:2022
ISO 27001:2022 A.5.15 - Supplier relationships ISO 27001:2022 A.8.1 - User endpoint devices ISO 27001:2022 A.8.2 - Privileged access rights ISO 27001:2022 A.8.3 - Information access restriction ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Ensure security patches are installed within one month of release PCI DSS 6.5.1 - Injection flaws prevention PCI DSS 6.5.10 - Broken authentication prevention PCI DSS 11.2 - Vulnerability scanning
📊 CVSS Score
7.2
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity High
CVSS Score7.2
CWECWE-918
EPSS0.01%
Exploit No
Patch ✓ Yes
Published 2026-02-05
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
8.1
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-918
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.