The WordPress plugin Offload, AI & Optimize with Cloudflare Images has a PHP code-injection vulnerability tracked as CVE-2026-9860. It is not a Cloudflare product. An authenticated attacker with Author-level upload_files capability can abuse its settings path to inject PHP into wp-config.php and execute code on the server.
Vulnerability Overview and Scope of Impact
All versions through 1.10.2 are affected. The attacker must be authenticated as an Author or higher; this is not an unauthenticated flaw. Wordfence's CNA assessment is CVSS v3.1 8.8 HIGH.
Specific Impacts and Attack Scenarios
Attackers can exploit this vulnerability by obtaining an account with author privileges or higher on a WordPress site. By sending a request containing malicious `account-id` or `api-key` parameters, they can write unauthorized code to the `wp-config.php` file. This could lead to severe consequences such as backdoor installation, theft of sensitive information, alteration of site content, and even complete server compromise. Particularly on sites where multiple users post content, the risk of insider threat should also be considered.
Actions Engineers Should Take Immediately
Update to a release after 1.10.2 whose fix is confirmed in the WordPress plugin changeset. If immediate updating is impossible, disable the plugin and review Author-or-higher accounts, wp-config.php changes, added administrators, and plugin or theme changes. Follow the plugin's published update path rather than generic server commands.
📦