Impact
The Image Buzz plugin for WordPress lacks required authentication checks, allowing any user with network access to alter the Pixabay, Unsplash, and Pixels API keys configured by site administrators. By changing these keys, an attacker can redirect image requests to compromised or malicious accounts, potentially leading to service outages, unauthorized API usage, or data exfiltration through the image providers’ services.
Affected Systems
WordPress sites running the Image Buzz plugin from the vendor kamleshyadav and any plugin version up to and including 1.0.3 are affected. No additional versions are listed as vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity. The EPSS score is not provided, and it is not listed in the CISA KEV catalog. Exploitation likely occurs through unauthenticated HTTP requests that include the "pixabay_api", "unsplash_api", or "pixels_api" parameters, allowing an attacker to modify the stored API keys without possessing administrative credentials.
OpenCVE Enrichment