CVE-2026-1557Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 via the 'src' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-26); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-26: 1Mentions · 2026-03-03: 1Mentions · 2026-03-18: 1PoC Mentioned / Linked · 2026-03-18: 1Technical Details · 2026-02-26: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-18: 102-2603-0303-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1557 - high 🚨 WP Responsive Images <= 1.0 - Arbitrary File Read > WP Responsive Images plugin for WordPress <= 1.0 contains a path traversal caused by ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1557 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2026-1557 affects WP Responsive Images ≤ 1.0 by enabling arbitrary file read via path traversal; a PoC link is provided.

    00031111
    900 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-1557 (CVSS:7.5, HIGH) is Awaiting Analysis. The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 ..https://nvd.nist.gov/vuln/detail/CVE-2026-1557 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The WP Responsive Images plugin for WordPress is vulnerable to path traversal (CVE-2026-1557) with a CVSS score of 7.5, but no PoC, exploit, patch, or active exploitation is mentioned.

    0000021
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1557 The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 via the 'src' parameter. This makes it possible … https://www.cve.org/CVERecord?id=CVE-2026-1557

    Post summary

    The WP Responsive Images plugin for WordPress is vulnerable to path traversal via the 'src' parameter in all versions up to 1.0.

    00000112
    56.6K followersView on X

Explore more