CVE-2025-8723: Cloudflare Image Resizing <= 1.5.6 - Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook
The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hookrestpredispatch() method in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to inject arbitrary PHP into the codebase, achieving remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8723?
CVE-2025-8723 is rated as critical due to potential remote code execution vulnerabilities.
How do I fix CVE-2025-8723?
To fix CVE-2025-8723, update the Cloudflare Image Resizing plugin to version 1.5.7 or later.
What types of attacks can exploit CVE-2025-8723?
CVE-2025-8723 can be exploited by unauthenticated attackers to execute arbitrary code on the server.
Which versions of the Cloudflare Image Resizing plugin are affected by CVE-2025-8723?
CVE-2025-8723 affects all versions of the Cloudflare Image Resizing plugin up to and including 1.5.6.
Is authentication required to exploit CVE-2025-8723?
No, CVE-2025-8723 can be exploited without authentication.