Junglewise Threat Intelligence

CVE-2025-14486: PixelPlay plugin authorization bypass API key deletion

CVE-2025-14486 · Severity: medium · CVSS 5.3 · Published 2026-09-22

Executive brief

The PixelPlay WordPress plugin contains a flaw that allows attackers to delete critical API keys (such as those for Pixabay, Unsplash, and OpenAI) without proper authorization. An unauthenticated attacker can exploit this to disable key integrations that site administrators depend on, disrupting functionality or forcing reconfiguration.

Technical details

The plugin fails to implement authorization checks on the 'clear_api_type' parameter, allowing unauthenticated attackers to trigger arbitrary API key deletion. The vulnerability affects all versions up to 1.0.2 and requires no user interaction beyond a network request. Deletion of stored API keys results in loss of integration functionality without administrator action.

Affected products

  • PixelPlay PixelPlay up to and including 1.0.2

Timeline

  • 2025-09-22: disclosed

References