Find Unused Images Plugin Unauthorized Data Deletion Vulnerability (CVE-2025-11996) — Medium Severity

Understanding the Find Unused Images Plugin Vulnerability

A notable security flaw has been identified in the “Find Unused Images” plugin for WordPress. This vulnerability, tracked as CVE-2025-11996, allows unauthenticated attackers to delete all attachments from a website running the affected plugin. This means that even without logging in, a malicious actor could completely remove your site’s images and other uploaded files, leading to significant data loss and disruption.

The issue stems from missing security checks in the plugin’s `fui_delete_image()` and `fui_delete_all_images()` functions. These functions, intended for managing unused images, lacked proper authorization verification, inadvertently creating a pathway for unauthorized data removal.

CVE Details

  • Product: Find Unused Images plugin for WordPress
  • Published: November 11, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability impacts the Find Unused Images plugin for WordPress. All versions of the plugin up to, and including, 1.0.7 are affected by this security flaw. If you are using any of these versions, your website is at risk.

Current Status

This vulnerability has been formally analyzed and documented, indicating that its details are well-understood within the cybersecurity community. While the vulnerability itself is clear, ongoing vigilance is necessary to ensure affected systems are protected.

Severity Level

The vulnerability carries a Medium severity rating. While not critical, a medium severity flaw can still have a significant impact. In this case, the ability for unauthenticated users to delete all site attachments can lead to severe data loss, reputational damage, and operational disruption. It underscores the importance of addressing the issue promptly to prevent potential abuse.

Possible Solutions

To protect your WordPress website from this vulnerability, immediate action is recommended:

  1. Update the Plugin: The most crucial step is to update the “Find Unused Images” plugin to the latest available version. It is highly probable that a version greater than 1.0.7 includes a patch for this vulnerability. Always ensure your plugins are kept up to date to benefit from security fixes.
  2. Deactivate and Uninstall (If No Update): If no updated version beyond 1.0.7 is available, or if the plugin is no longer maintained, it is strongly advised to deactivate and uninstall the “Find Unused Images” plugin from your WordPress installation immediately to eliminate the risk entirely.

Regular backups of your WordPress site, especially your uploads folder, are always a good practice to mitigate the impact of any data loss incidents.

References

https://plugins.trac.wordpress.org/browser/find-unused-images/tags/1.0.7/inc/generic-functions.php#L44

https://plugins.trac.wordpress.org/browser/find-unused-images/tags/1.0.7/inc/generic-functions.php#L53

https://wordpress.org/plugins/find-unused-images/

https://www.wordfence.com/threat-intel/vulnerabilities/id/3aa1964e-97e9-4166-89d5-788b336790b6?source=cve

https://wordpress.org/plugins/find-unused-images/

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.