Missing Authorization Vulnerability in GrandPlugins Image Sizes Controller from WordPress
CVE-2025-49973
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 June 2025
What is CVE-2025-49973?
A missing authorization vulnerability exists in the GrandPlugins Image Sizes Controller plugin for WordPress, affecting its Create Custom Image Sizes and Disable Image Sizes functionalities. This flaw allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions and data exposure. Versions from n/a through 1.0.9 are affected, emphasizing the need for vigilance in verifying access configurations.
Affected Version(s)
Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes <= 1.0.9