Missing Authorization Vulnerability in Anton Vanyukov's Offload, AI & Optimize Plugin for Cloudflare Images
CVE-2025-66104

6.5MEDIUM

What is CVE-2025-66104?

A missing authorization vulnerability exists in the Offload, AI & Optimize with Cloudflare Images plugin developed by Anton Vanyukov. This issue allows an attacker to exploit incorrectly configured access control security levels, potentially exposing sensitive information or enabling unauthorized actions. The vulnerability affects versions of the plugin up to and including 1.9.5, posing a risk to sites utilizing this integration with Cloudflare Images.

Affected Version(s)

Offload, AI &amp; Optimize with Cloudflare Images <= n/a

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan | Patchstack Bug Bounty Program
.