CVE 9.8 CRITICAL

Cloudflare Image Resizing <= 1.5.6 - Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook_CVE-2025-8723

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to inject arbitrary PHP into the codebase, achieving remote code execution.

Basic Information

ID CVE-2025-8723
Source Wordfence
Published Aug 19, 2025 at 07:26

Affected Product

Vendor mecanik
Product Cloudflare Image Resizing – Optimize & Accelerate Your Images
Version *
Affected Versions mecanik Cloudflare Image Resizing – Optimize & Accelerate Your Images *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.