Junglewise Threat Intelligence

CVE-2025-14484: Image Buzz plugin for WordPress authorization bypass in API key management

CVE-2025-14484 · Severity: medium · CVSS 5.3 · Published 2026-09-22

Executive brief

The Image Buzz WordPress plugin allows unauthenticated attackers to modify API keys for image services (Pixabay, Unsplash, Pixels) that site administrators have configured. An attacker could redirect the site's image searches to malicious sources, disrupt service, or gather intelligence about the site's configuration. This affects all versions up to 1.0.3.

Technical details

The plugin lacks authorization checks on the API key modification endpoints, allowing unauthenticated attackers to modify the 'pixabay_api', 'unsplash_api', and 'pixels_api' parameters. An attacker can exploit this via direct HTTP requests without authentication. Exploitation results in modification of administrator-configured credentials, disrupting functionality and potentially enabling service hijacking.

Affected products

  • Image Buzz Image Buzz up to 1.0.3

Timeline

  • 2026-09-22: disclosed

References