Impact
The vulnerability is a missing authorization flaw that allows an attacker to circumvent the plugin’s access control. This broken access control can enable the attacker to read or modify data that should be protected by the plugin, potentially compromising sensitive content or user information. The weakness aligns with CWE‑862, which classifies it as an improper authorization flaw.
Affected Systems
The affected product is the WordPress plugin "Offload, AI & Optimize with Cloudflare Images" developed by Anton Vanyukov, versions up to and including 1.9.5 are impacted. No other products or vendors are specifically listed as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not currently in the CISA KEV catalog. Although the exact attack vector is not detailed in the official description, it is reasonable to infer that the flaw can be exploited via standard web requests to the plugin’s endpoints, given the nature of broken access control in a WordPress plugin.
OpenCVE Enrichment