Unauthorized API Key Deletion in PixelPlay Plugin for WordPress
CVE-2025-14486
5.3MEDIUM
What is CVE-2025-14486?
The PixelPlay plugin for WordPress is susceptible to unauthorized deletion of API keys due to inadequate authorization controls. All versions up to and including 1.0.2 allow unauthenticated users to execute the 'clear_api_type' function, enabling them to delete API keys linked to various services like Pixabay, Unsplash, Pixels, and OpenAI. This vulnerability poses a significant risk to site administrators who may lose access to essential functions and integrations.
Affected Version(s)
PixelPlay 0 <= 1.0.2