9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to inject arbitrary PHP into the codebase, achieving remote code execution.
Basic Information
ID
CVE-2025-8723
Source
Wordfence
Published
Aug 19, 2025 at 07:26
Affected Product
Vendor
mecanik
Product
Cloudflare Image Resizing – Optimize & Accelerate Your Images
Version
*
Affected Versions
mecanik Cloudflare Image Resizing – Optimize & Accelerate Your Images *