Executive brief
The Image Buzz WordPress plugin allows unauthenticated attackers to modify API keys for image services (Pixabay, Unsplash, Pixels) that site administrators have configured. An attacker could redirect the site's image searches to malicious sources, disrupt service, or gather intelligence about the site's configuration. This affects all versions up to 1.0.3.
Technical details
The plugin lacks authorization checks on the API key modification endpoints, allowing unauthenticated attackers to modify the 'pixabay_api', 'unsplash_api', and 'pixels_api' parameters. An attacker can exploit this via direct HTTP requests without authentication. Exploitation results in modification of administrator-configured credentials, disrupting functionality and potentially enabling service hijacking.
Affected products
- Image Buzz Image Buzz up to 1.0.3
Timeline
- 2026-09-22: disclosed