LH Cache Remote Images

Description

LH Cache Remote Images allows you to scan a post, page, or cpt to fetch remote images; then updates its content.

Unlike other similar plugins this plugin adds the images and updates post_content asynchronously. Thus ensuring the publishing experience is not slowed down.

Credits

Thanks to Philipp Beick for responsibly disclosing an SSRF and unsafe-SQL-construction issue affecting version 1.04, addressed in 1.10.

Installation

Install using WordPress:

  1. Log in and go to Plugins and click on Add New.
  2. Search for LH Cache Remote Images and hit the Install Now link in the results. WordPress will install it.
  3. That is it

FAQ

Q: Will it archive the images which are already hosted on my blog ?
A: No, only the external images.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“LH Cache Remote Images” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

Full version history is maintained in CHANGELOG.md. Recent versions:

1.11 August 1, 2026
WordPress Plugin Check compliance pass: added License headers, corrected “Requires at least” to match the plugin’s real minimum WordPress version (5.8.1), removed a stale Domain Path pointing at a nonexistent languages folder, escaped debug output, removed a dead unused method calling a nonexistent function, added a missing direct-file-access guard, added missing text-domain arguments, and replaced discouraged parse_url()/unlink() calls with their WordPress-API equivalents.

1.10 July 31, 2026
Security fixes for an SSRF vulnerability and unsafe SQL construction responsibly disclosed by Philipp Beick, plus an additional related SSRF bypass and host-matching bypass found during review; removed unused bundled taxonomy library; added plugin_version() identity method. (Versioned 1.10, not 1.1.0, because WordPress’s version comparison was treating the legacy 1.04 as newer than 1.1.0.)

1.04 October 08, 2017
Updated lh-copy-from-url-class.php

1.03 September 10, 2017
Check posttype is public