CVE-2025-14482: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14482 is a Missing Authorization vulnerability in the Crush.pics Image Optimizer – Image Compression and Optimization plugin for WordPress. It affects all versions up to and including 1.8.7, allowing authenticated attackers with Subscriber-level access or above to make unauthorized modifications to plugin settings. The vulnerability was published on January 14, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): multiple AJAX handler functions in inc/class-ajax.php (notably at lines 30, 66, and 193) lack proper capability checks before processing requests (Wordfence). An authenticated attacker with at minimum Subscriber-level WordPress credentials can send crafted requests to these unprotected endpoints over the network without any user interaction. The missing checks allow the attacker to alter plugin configuration, such as disabling auto-compression or changing image quality settings, actions that should be restricted to administrators.

Impact

Successful exploitation results in unauthorized modification of plugin settings, impacting the integrity of the WordPress site's image optimization configuration. An attacker could disable auto-compression or degrade image quality settings, potentially affecting site performance and user experience. There is no confidentiality or availability impact identified; the scope is limited to the plugin's configuration data (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14482. The EPSS score is approximately 0.026%, indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a valid Subscriber-level WordPress account, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Obtain credentials: Register or obtain a Subscriber-level (or higher) account on the target WordPress site running Crush.pics Image Optimizer ≤ 1.8.7.
  2. Identify vulnerable endpoints: Review the plugin's AJAX handler file (inc/class-ajax.php) at lines 30, 66, and 193 to identify the specific WordPress AJAX actions registered without capability checks.
  3. Craft a malicious request: Send an authenticated HTTP POST request to wp-admin/admin-ajax.php with the appropriate action parameter corresponding to one of the unprotected functions (e.g., to disable auto-compression or change image quality).
  4. Modify plugin settings: The server processes the request without verifying the user's authorization level, applying the attacker-specified configuration changes to the plugin settings (Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to wp-admin/admin-ajax.php with plugin-specific action parameters from low-privileged user accounts (Subscriber role).
  • Application: Unexpected changes to Crush.pics plugin settings (e.g., auto-compression disabled, image quality altered) without corresponding administrator activity in the WordPress audit log.
  • Network: Repeated or scripted POST requests to wp-admin/admin-ajax.php from the same authenticated session targeting Crush.pics AJAX actions.

Mitigation and workarounds

Users should update the Crush.pics Image Optimizer plugin to a version beyond 1.8.7 that includes proper capability checks on all AJAX handler functions. Until a patched version is available or applied, site administrators can restrict Subscriber-level user registration or remove untrusted subscriber accounts to reduce exposure. Monitoring WordPress user activity and plugin settings changes is also recommended as a compensating control (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93549HIGH8.8
  • cart-rest-api-for-woocommerce
NoYesOct 04, 2026
CVE-2026-78371MEDIUM5.9
  • woo-addon-uploads
NoYesOct 05, 2026
CVE-2026-13607MEDIUM5.9
  • woo-addon-uploads
NoNoOct 05, 2026
CVE-2026-84169MEDIUM5.3
  • upi-qr-code-payment-gateway
NoNoOct 05, 2026
CVE-2026-97332MEDIUM5.3
  • user-private-files
NoYesOct 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management