Known vulnerabilities in Import external attachments
Makes local copies of all the linked images and pdfs in a post, adding them as gallery attachments.
2Reported vulnerabilities
4.3Highest CVSS score
1.5.12Latest version
1,000+Active installs
What to do now
Update Import external attachments to 1.5.12 or later.
Some of these have no published fix. Update to the latest version and check the vendor advisory.
This plugin has not been updated in over two years. New vulnerabilities may never be fixed. Consider an alternative.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-64245 | Medium | 0.2% | 1.5.12 and earlier | — | December 14, 2025 |
| CVE-2025-53268 | Medium | 0.1% | 1.5.12 and earlier | — | June 27, 2025 |