What the vulnerability does
01Description
Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes image-sizes-controller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a through <= 1.0.10.
Explanation of Vulnerability in Simple Terms
02Summary
The Image Sizes Controller and related plugins from GrandPlugins contain a missing authorization check that allows authenticated users with low privileges to modify image size settings. An attacker with a basic user account can change how images are processed on the site without proper permission validation. This affects versions up to 1.0.10.
What an attacker can do
03Attacker Capabilities
Modify image size settings and processing rules on the site.
Potential impact on your site
04Site Impact
Unauthorized users can alter image handling, potentially breaking site appearance or redirecting image processing.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
June 20, 2025
CVE published
May 12, 2026
Record updated