
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14482 is a Missing Authorization vulnerability in the Crush.pics Image Optimizer – Image Compression and Optimization plugin for WordPress. It affects all versions up to and including 1.8.7, allowing authenticated attackers with Subscriber-level access or above to make unauthorized modifications to plugin settings. The vulnerability was published on January 14, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization): multiple AJAX handler functions in inc/class-ajax.php (notably at lines 30, 66, and 193) lack proper capability checks before processing requests (Wordfence). An authenticated attacker with at minimum Subscriber-level WordPress credentials can send crafted requests to these unprotected endpoints over the network without any user interaction. The missing checks allow the attacker to alter plugin configuration, such as disabling auto-compression or changing image quality settings, actions that should be restricted to administrators.
Successful exploitation results in unauthorized modification of plugin settings, impacting the integrity of the WordPress site's image optimization configuration. An attacker could disable auto-compression or degrade image quality settings, potentially affecting site performance and user experience. There is no confidentiality or availability impact identified; the scope is limited to the plugin's configuration data (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14482. The EPSS score is approximately 0.026%, indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a valid Subscriber-level WordPress account, which limits the attack surface compared to unauthenticated vulnerabilities.
inc/class-ajax.php) at lines 30, 66, and 193 to identify the specific WordPress AJAX actions registered without capability checks.wp-admin/admin-ajax.php with the appropriate action parameter corresponding to one of the unprotected functions (e.g., to disable auto-compression or change image quality).wp-admin/admin-ajax.php with plugin-specific action parameters from low-privileged user accounts (Subscriber role).wp-admin/admin-ajax.php from the same authenticated session targeting Crush.pics AJAX actions.Users should update the Crush.pics Image Optimizer plugin to a version beyond 1.8.7 that includes proper capability checks on all AJAX handler functions. Until a patched version is available or applied, site administrators can restrict Subscriber-level user registration or remove untrusted subscriber accounts to reduce exposure. Monitoring WordPress user activity and plugin settings changes is also recommended as a compensating control (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."