plugin

Image Resizer On The Fly Vulnerabilities

2 known security issues reported for the Image Resizer On The Fly WordPress plugin. Most recent disclosed Jun 13, 2025.

1 critical

Running Image Resizer On The Fly on your site? Check whether your installed version is affected.

Scan your site free

Image Resizer On The Fly <= 1.1 - Unauthenticated Arbitrary File Deletion

critical

The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' task in all versions up to, and including, 1.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remot...

CVSS:
9.1
Affected:
up to 1.1
Fix:
No patched version reported
Disclosed:
Jun 13, 2025

CVE-2025-6065 on NVD →

Image Resizer On The Fly [image-resizer-on-the-fly] <= 1.1 (unfixed + closed)

unknown
Affected:
up to 1.1
Fix:
No patched version reported

CVE-2025-6065 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database