Missing Authorization Vulnerability in Anton Vanyukov's Offload, AI & Optimize Plugin for Cloudflare Images
CVE-2025-66104
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 December 2025
What is CVE-2025-66104?
A missing authorization vulnerability exists in the Offload, AI & Optimize with Cloudflare Images plugin developed by Anton Vanyukov. This issue allows an attacker to exploit incorrectly configured access control security levels, potentially exposing sensitive information or enabling unauthorized actions. The vulnerability affects versions of the plugin up to and including 1.9.5, posing a risk to sites utilizing this integration with Cloudflare Images.
Affected Version(s)
Offload, AI & Optimize with Cloudflare Images <= n/a