Remote Code Execution in Cloudflare Images Plugin for WordPress
CVE-2026-9860
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 June 2026
What is CVE-2026-9860?
The Cloudflare Images plugin for WordPress is susceptible to a remote code execution vulnerability due to inadequate privilege checks on the cf_images_do_setup AJAX handler. This weakness affects all versions up to and including 1.10.2. Authenticated users with author-level access can trigger the vulnerability via the 'account-id' parameter, which does not properly sanitize input. As a result, this allows an attacker to execute arbitrary code on the server by leveraging the exposed nonce and writing directly to the wp-config.php file. This exploit results from inadequate enforcement of user privileges, allowing unauthorized code execution through the plugin.
Affected Version(s)
Offload, AI & Optimize with Cloudflare Images 0 <= 1.10.2