Missing Authorization Vulnerability in GrandPlugins Image Sizes Controller from WordPress
CVE-2025-49973
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 June 2025
What is CVE-2025-49973?
A missing authorization vulnerability exists in the GrandPlugins Image Sizes Controller plugin for WordPress, affecting its Create Custom Image Sizes and Disable Image Sizes functionalities. This flaw allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions and data exposure. Versions from n/a through 1.0.9 are affected, emphasizing the need for vigilance in verifying access configurations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes <= 1.0.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved