CVE-2025-14484
Received Received - Intake

Unauthorized API Key Modification in Image Buzz WordPress Plugin

Vulnerability report for CVE-2025-14484, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: Wordfence

Description

The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify arbitrary API keys (Pixabay, Unsplash, Pixels) configured by site administrators via the 'pixabay_api', 'unsplash_api', or 'pixels_api' parameters.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
imagbuzz image_buzz to 1.0.3 (inc)
image_buzz image_buzz_plugin to 1.0.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Image Buzz WordPress plugin up to version 1.0.3 has a flaw where it lacks proper authorization checks. This allows unauthenticated attackers to modify API keys used for services like Pixabay, Unsplash, and Pixels by manipulating specific parameters in the plugin.

Detection Guidance

Check WordPress plugin files for unauthorized modifications to API keys. Look for POST requests to /wp-json/imagbuzz/v1/update_api_keys with parameters pixabay_api, unsplash_api, or pixels_api. Review server logs for suspicious activity targeting the Image Buzz plugin.

Impact Analysis

If you use this plugin, attackers could change your API keys without needing access. This might disrupt image services on your site or lead to unauthorized usage of your API accounts, potentially causing service disruptions or unexpected charges.

Compliance Impact

This vulnerability allows unauthenticated attackers to modify API keys, which could lead to unauthorized access to image data or services. While not directly impacting GDPR or HIPAA compliance, unauthorized access to data could result in data breaches, potentially violating these regulations if sensitive data is exposed.

Mitigation Strategies

Update the Image Buzz plugin to the latest version if available. Remove or disable the plugin if no update exists. Restrict access to WordPress admin panels and API endpoints. Monitor API keys for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-14484. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart