VYPR
Medium severity6.5NVD Advisory· Published Dec 18, 2025· Updated Apr 28, 2026

CVE-2025-66104

CVE-2025-66104

Description

Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Offload, AI & Optimize with Cloudflare Images: from n/a through <= 1.9.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Offload, AI & Optimize with Cloudflare Images plugin (≤1.9.5) allows unauthenticated access control bypass.

The vulnerability is a missing authorization check in the WordPress plugin 'Offload, AI & Optimize with Cloudflare Images' (cf-images) versions up to 1.9.5. This allows attackers to bypass access control security levels [1].

An unauthenticated attacker can exploit this by sending crafted requests to plugin functions lacking proper authorization checks, requiring no special privileges or network position [1].

Successful exploitation could allow an attacker to perform actions intended for higher-privileged users, such as modifying plugin settings or accessing sensitive data, potentially leading to site compromise [1].

The vendor has released version 1.9.6 to fix the issue. Users are advised to update immediately. Patchstack also provides a mitigation rule to block attacks until patching [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.