Missing Authorization Vulnerability in Anton Vanyukov's Offload, AI & Optimize Plugin for Cloudflare Images
CVE-2025-66104
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 December 2025
What is CVE-2025-66104?
A missing authorization vulnerability exists in the Offload, AI & Optimize with Cloudflare Images plugin developed by Anton Vanyukov. This issue allows an attacker to exploit incorrectly configured access control security levels, potentially exposing sensitive information or enabling unauthorized actions. The vulnerability affects versions of the plugin up to and including 1.9.5, posing a risk to sites utilizing this integration with Cloudflare Images.
Affected Version(s)
Offload, AI & Optimize with Cloudflare Images <= n/a
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nabil Irawan | Patchstack Bug Bounty Program