CVE-2026-9860
vanyukov Offload, AI & Optimize with Cloudflare Images
The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the upload_files capability (Author+) rather than manage_options before writing to wp-config.php, combined with the absence of single-quote escaping — sanitize_text_field() does not strip single quotes, and filter_input(INPUT_POST) bypasses wp_magic_quotes() slashing — allowing a single qu...
- CVSS
- 8.8
- EPSS
- 0.58% 43.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.18