FORSMILE
JA
セキュリティ2026/07/01

[URGENT] WordPress Offload, AI & Optimize with Cloudflare Images CVE-2026-9860: Install a Fixed Release

This third-party WordPress plugin allows an authenticated Author-level user to execute code. Versions through 1.10.2 are affected; it is not a Cloudflare product.

← Back to Blog

The WordPress plugin Offload, AI & Optimize with Cloudflare Images has a PHP code-injection vulnerability tracked as CVE-2026-9860. It is not a Cloudflare product. An authenticated attacker with Author-level upload_files capability can abuse its settings path to inject PHP into wp-config.php and execute code on the server.

Vulnerability Overview and Scope of Impact

All versions through 1.10.2 are affected. The attacker must be authenticated as an Author or higher; this is not an unauthenticated flaw. Wordfence's CNA assessment is CVSS v3.1 8.8 HIGH.

⚠ CVE Score — 高危険度 / HIGH
8.8HIGHCVSS v3.1CVE-2026-9860

Specific Impacts and Attack Scenarios

Attackers can exploit this vulnerability by obtaining an account with author privileges or higher on a WordPress site. By sending a request containing malicious `account-id` or `api-key` parameters, they can write unauthorized code to the `wp-config.php` file. This could lead to severe consequences such as backdoor installation, theft of sensitive information, alteration of site content, and even complete server compromise. Particularly on sites where multiple users post content, the risk of insider threat should also be considered.

Actions Engineers Should Take Immediately

Update to a release after 1.10.2 whose fix is confirmed in the WordPress plugin changeset. If immediate updating is impossible, disable the plugin and review Author-or-higher accounts, wp-config.php changes, added administrators, and plugin or theme changes. Follow the plugin's published update path rather than generic server commands.

📦
Search Amazon US for related books and tools
cybersecurity server security tools
Search Amazon US → (affiliate link). As an Amazon Associate, we earn from qualifying purchases.

References and Official Patch Information

Related articles