CVE Details
Basic Information
| Title | Image Resizer On The Fly <= 1.1 - Unauthenticated Arbitrary File Deletion |
|---|---|
| Type | cve |
| Published | 2025-06-14T08:23:21.618Z |
| Last Seen |
Product Information
| Vendor | wework4web |
|---|---|
| Product | Image Resizer On The Fly |
| Version | * |
CVSS Information
| Base Score | 9.1 (CRITICAL) |
|---|---|
| Attack Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ‘delete’ task in all versions up to, and including, 1.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). |
|---|---|
| AI Severity | Critical |
| Vendor | WordPress Community |
| Product | Image Resizer On The Fly |
| Affected Version | <= 1.1 |
Affected Products
- wework4web Image Resizer On The Fly *
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-22 |
| Bulletin Family |
References
Description
The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ‘delete’ task in all versions up to, and including, 1.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).