Medium severity4.3NVD Advisory· Published Jan 14, 2026· Updated Apr 15, 2026
CVE-2025-14482
CVE-2025-14482
Description
The Crush.pics Image Optimizer - Image Compression and Optimization plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on multiple functions in all versions up to, and including, 1.8.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify plugin settings including disabling auto-compression and changing image quality settings.
Affected products
2- Range: <=1.8.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- plugins.trac.wordpress.org/browser/crush-pics/trunk/inc/class-ajax.phpnvd
- plugins.trac.wordpress.org/browser/crush-pics/trunk/inc/class-ajax.phpnvd
- plugins.trac.wordpress.org/browser/crush-pics/trunk/inc/class-ajax.phpnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/5e71bf15-aee0-4efc-a1c6-faad9f6e4f38nvd
News mentions
0No linked articles in our index yet.