
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-8723 is a Remote Code Execution (RCE) vulnerability in the Cloudflare Image Resizing plugin for WordPress, affecting all versions up to and including 1.5.6. The flaw stems from missing authentication and insufficient input sanitization in the plugin's hook_rest_pre_dispatch() method, enabling unauthenticated attackers to inject arbitrary PHP code into the codebase. It was published on August 19, 2025, with a CVSS v3.1 base score of 9.8 (Critical) (Red Hat CVE, Vulners).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The vulnerable hook_rest_pre_dispatch() method in the plugin fails to authenticate incoming REST API requests and does not adequately sanitize user-supplied input, allowing an attacker to inject arbitrary PHP code directly into the WordPress codebase via a crafted network request. No privileges or user interaction are required, and attack complexity is low, making this trivially exploitable over the network. A public proof-of-concept exploit is available on GitHub (GitHub PoC, CIRCL Advisory).
Successful exploitation results in complete compromise of the affected WordPress installation — attackers gain full confidentiality, integrity, and availability impact. An unauthenticated attacker can execute arbitrary commands on the web server, install malware or backdoors, exfiltrate sensitive data (including database credentials and user information), modify or delete site content, and potentially pivot to other systems accessible from the compromised host (Red Hat CVE, Feedly Intelligence).
A proof-of-concept exploit was published on GitHub (https://github.com/Nxploited/CVE-2025-8723) shortly after disclosure, and the vulnerability was added to Qualys web application detection coverage in August 2025. As of available data, there is no confirmed evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.36%, though the public PoC availability and critical CVSS score elevate practical risk. The vulnerability was also referenced in a CISA vulnerability bulletin for the week of August 18, 2025 (CISA Bulletin, GitHub PoC, Qualys).
/wp-content/plugins/cloudflare-image-resizing/.hook_rest_pre_dispatch() method, which lacks authentication checks./wp-content/plugins/cloudflare-image-resizing/ or other writable WordPress directories; web shells or obfuscated PHP scripts in the WordPress installation tree.eval() execution.bash, curl, wget, python) not associated with normal WordPress operation (GitHub PoC).Update the Cloudflare Image Resizing plugin to a version newer than 1.5.6 as soon as a patched release is available. If no patch is currently available, immediately disable or remove the plugin from the WordPress installation to eliminate the attack surface. As an additional layer of defense, implement web application firewall (WAF) rules to restrict or monitor REST API access to the affected plugin endpoints. Monitor WordPress and server logs for anomalous REST API activity and conduct integrity checks on plugin files (Red Hat CVE, CISA Bulletin).
The vulnerability was noted in a CISA weekly vulnerability bulletin for the week of August 18, 2025, and picked up by security aggregators including Vulners, VulDB, and CVEFeed shortly after disclosure. Check Point published a defense advisory (CPAI-2025-12172) covering this CVE. Community discussion was observed on Infosec.Exchange and security blogs such as tonyharris.io's PoC Week roundup. No major vendor statements beyond the CVE disclosure itself have been identified (CISA Bulletin, Check Point Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."