PT-2025-46268 · WordPress · Find Unused Images

Johska

·

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-11996

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Find Unused Images plugin for WordPress versions through 1.0.7
Description The Find Unused Images plugin for WordPress is susceptible to unauthorized data loss. This is due to a missing capability check within the fui delete image() and fui delete all images() functions. This allows unauthenticated attackers to delete all attachments associated with a WordPress site.
Recommendations Update the Find Unused Images plugin to a version later than 1.0.7.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-11996

Affected Products

Find Unused Images