CVE-2026-24560: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24560 is a Missing Authorization (Broken Access Control) vulnerability in the Cloudinary WordPress plugin (cloudinary-image-management-and-manipulation-in-the-cloud-cdn). It allows authenticated attackers with low privileges (e.g., Subscriber role) to exploit incorrectly configured access control security levels, potentially performing actions beyond their intended permissions. The vulnerability affects all plugin versions up to and including 3.3.2, with the initial disclosure covering versions up to 3.3.0 before being updated. It was published on January 23, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium), assigned by Patchstack (Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning one or more plugin functions lack proper authorization, authentication, or nonce token checks before executing privileged operations. This allows a low-privileged authenticated user (Subscriber level or above) to invoke functionality that should be restricted to higher-privileged roles such as administrators. The attack vector is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit once an attacker has any valid WordPress account on the target site. The vulnerability was discovered by security researcher Nabil Irawan and reported to Patchstack on December 23, 2025 (Patchstack).

Impact

Successful exploitation results in limited but meaningful integrity and availability impacts — an authenticated low-privileged attacker can perform unauthorized actions within the Cloudinary plugin's functionality, such as modifying image management settings or disrupting media delivery configurations. Confidentiality is not directly impacted per the CVSS assessment (C:N). The scope is limited to the affected WordPress installation, but in a shared hosting or multi-tenant environment, unauthorized manipulation of Cloudinary settings could affect media assets served site-wide (Patchstack).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.025% (0.000250), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies it as low priority with "no impactful threat," though they note that broken access control vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Cloudinary plugin version <= 3.3.2 using tools like WPScan, Shodan, or by checking the plugin's readme.txt file exposed at wp-content/plugins/cloudinary-image-management-and-manipulation-in-the-cloud-cdn/readme.txt.
  2. Obtain low-privileged access: Register or obtain credentials for a low-privileged WordPress account (e.g., Subscriber role), which may be available on sites with open registration.
  3. Identify unprotected endpoints: Enumerate WordPress AJAX actions or REST API endpoints registered by the Cloudinary plugin that lack capability checks or nonce validation.
  4. Send unauthorized request: Craft and send an authenticated HTTP request (with valid WordPress session cookies or nonce) to the vulnerable endpoint, invoking a privileged action such as modifying plugin settings or media configurations.
  5. Achieve unauthorized action: The server processes the request without verifying the user's authorization level, resulting in unauthorized modification of Cloudinary plugin settings or disruption of media management functionality (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to wp-admin/admin-ajax.php or REST API endpoints (/wp-json/) from low-privileged user accounts targeting Cloudinary plugin actions at unusual times or frequencies.
  • Logs: WordPress debug logs or error logs showing unexpected capability checks being bypassed or missing nonce validation warnings related to the Cloudinary plugin.
  • File System: Unexpected changes to Cloudinary plugin configuration files or WordPress options table entries (wp_options) related to Cloudinary settings (e.g., cloudinary_connect, cloudinary_settings).
  • Network: Unusual outbound connections from the WordPress server to Cloudinary API endpoints initiated by non-administrative user sessions.

Mitigation and workarounds

As of the time of disclosure, no official patched version of the Cloudinary WordPress plugin was available — the Patchstack advisory notes "No official patch available" for versions <= 3.3.2. Site administrators should monitor the WordPress plugin repository for an updated version and apply it immediately upon release. As a workaround, consider disabling the Cloudinary plugin until a patch is available, restricting WordPress user registration to prevent untrusted low-privileged accounts, or deploying a Web Application Firewall (WAF) rule via Patchstack or similar solutions to virtually patch the vulnerability (Patchstack).

Community reactions

The vulnerability was discovered by independent researcher Nabil Irawan and disclosed through Patchstack's coordinated vulnerability disclosure process. Patchstack classifies it as low priority with limited exploitation likelihood, and the NVD notes it is "not being prioritized for NVD enrichment efforts due to resource or other concerns." No significant vendor statements from Cloudinary, broader media coverage, or notable community discussion has been identified for this vulnerability (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management