{"id":"CVE-2025-14484","title":"The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3","summary":"The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify arbitr…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"vendor":"kamleshyadav","product":"Image Buzz","affected":["image_buzz <= 1.0.3"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T19:04:55.677","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14484","references":[{"url":"https://codecanyon.net/item/image-buzz-free-stock-images-wordpress-plugin/42500370","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3d1c7383-ac3b-48b3-aaea-729a36e77ff5?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-22T10:09:28.008719Z"},"ingestedAt":"2026-09-22T08:00:27.694Z","epss":0.0023,"epssPercentile":0.14038,"slug":"CVE-2025-14484","body":"## Overview\n\nThe Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify arbitrary API keys (Pixabay, Unsplash, Pixels) configured by site administrators via the 'pixabay_api', 'unsplash_api', or 'pixels_api' parameters.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}