Executive brief
The PixelPlay WordPress plugin contains a flaw that allows attackers to delete critical API keys (such as those for Pixabay, Unsplash, and OpenAI) without proper authorization. An unauthenticated attacker can exploit this to disable key integrations that site administrators depend on, disrupting functionality or forcing reconfiguration.
Technical details
The plugin fails to implement authorization checks on the 'clear_api_type' parameter, allowing unauthenticated attackers to trigger arbitrary API key deletion. The vulnerability affects all versions up to 1.0.2 and requires no user interaction beyond a network request. Deletion of stored API keys results in loss of integration functionality without administrator action.
Affected products
- PixelPlay PixelPlay up to and including 1.0.2
Timeline
- 2025-09-22: disclosed