Remote Code Execution in Cloudflare Images Plugin for WordPress
CVE-2026-9860

8.8HIGH

What is CVE-2026-9860?

The Cloudflare Images plugin for WordPress is susceptible to a remote code execution vulnerability due to inadequate privilege checks on the cf_images_do_setup AJAX handler. This weakness affects all versions up to and including 1.10.2. Authenticated users with author-level access can trigger the vulnerability via the 'account-id' parameter, which does not properly sanitize input. As a result, this allows an attacker to execute arbitrary code on the server by leveraging the exposed nonce and writing directly to the wp-config.php file. This exploit results from inadequate enforcement of user privileges, allowing unauthorized code execution through the plugin.

Affected Version(s)

Offload, AI & Optimize with Cloudflare Images 0 <= 1.10.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yat Wu
.