๐Ÿ” CVE Alert

CVE-2025-49973

UNKNOWN 0.0

WordPress Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes plugin <= 1.0.10 - Broken Access Control Vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes image-sizes-controller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a through <= 1.0.10.

CWE CWE-862
Vendor grandplugins
Product image sizes controller, create custom image sizes, disable image sizes
Published Jun 20, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for grandplugins image sizes controller, create custom image sizes, disable image sizes

Be the first to know when new unknown vulnerabilities affecting grandplugins image sizes controller, create custom image sizes, disable image sizes are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

GrandPlugins / Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes
0 โ‰ค 1.0.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/image-sizes-controller/vulnerability/wordpress-image-sizes-controller-create-custom-image-sizes-disable-image-sizes-plugin-1-0-9-broken-access-control-vulnerability?_s_id=cve

Credits

ch4r0n | Patchstack Bug Bounty Program