The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() functiosn in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to delete all of a site's attachments.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toastwebsites
Toastwebsites find Unused Images |
|
| CPEs | cpe:2.3:a:toastwebsites:find_unused_images:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Toastwebsites
Toastwebsites find Unused Images |
Wed, 12 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Tue, 11 Nov 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() functiosn in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to delete all of a site's attachments. | |
| Title | Find Unused Images <= 1.0.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-11-12T20:08:23.692Z
Reserved: 2025-10-20T20:44:00.939Z
Link: CVE-2025-11996
Updated: 2025-11-12T16:52:43.100Z
Status : Analyzed
Published: 2025-11-11T04:15:45.130
Modified: 2025-12-22T15:03:56.050
Link: CVE-2025-11996
No data.
OpenCVE Enrichment
Updated: 2025-11-12T12:47:41Z