CVE-2025-8723 Information
Description
The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in all versions up to and including 1.5.6. This makes it possible for unauthenticated attackers to inject arbitrary PHP into the codebase achieving remote code execution.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://plugins.trac.wordpress.org/changeset/3337593/ https://plugins.trac.wordpress.org/changeset/3341917/ https://wordpress.org/plugins/cf-image-resizing/#developers https://www.wordfence.com/threat-intel/vulnerabilities/id/0f3b3c1a-1d45-4e2f-854a-171fe759257b?source=cve
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Related CNNVD
CNNVD-202508-2084 (Published: 2025-08-19)
Share on: