CVE-2025-14486: PixelPlay <= 1.0.2 - Missing Authorization to Unauthenticated Arbitrary API Key Deletion via 'clear_api_type' Parameter
The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to delete arbitrary API keys (Pixabay, Unsplash, Pixels, OpenAI) configured by site administrators via the 'clearapitype' parameter.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to this issue?
WordPress sites using the PixelPlay plugin in version 1.0.2 or earlier are affected if they have API keys configured for Pixabay, Unsplash, Pixels, or OpenAI.
What does an attacker need to exploit the issue?
An attacker does not need authentication or user interaction. They need to send a request using the clear_api_type parameter to target configured API keys.
What is the impact of a successful attack?
An attacker can delete API keys configured by a site administrator for the affected services. The provided information indicates an integrity impact and does not indicate confidentiality or availability impact.