← Back to browse · API

CVE-2025-8723

Severity
CRITICAL
CVSS
9.8
EPSS
0.14731
Risk score
44.36
CISA KEV
No
PoC
No
Published
2025-08-19
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2025-28804, GHSA-52W9-QFC2-5XQ5
Products
mecanik:Cloudflare Image Resizing – Optimize & Accelerate Your Images 0 ≤1.5.6
Sources
euvd EUVD-2025-28804

Description

The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to inject arbitrary PHP into the codebase, achieving remote code execution.

References