Title: Missing Authorization
Last modified: December 15, 2025

---

# Missing Authorization

 *  [viktoriwan](https://wordpress.org/support/users/viktoriwan/)
 * (@viktoriwan)
 * [5 months, 3 weeks ago](https://wordpress.org/support/topic/missing-authorization-2/)
 * The Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes plugin
   for WordPress is vulnerable to unauthorized access due to a missing capability
   check on a function in all versions up to, and including, 1.0.10. This makes 
   it possible for authenticated attackers, with Subscriber-level access and above,
   to perform an unauthorized action.
    -  This topic was modified 5 months, 3 weeks ago by [viktoriwan](https://wordpress.org/support/users/viktoriwan/).
    -  This topic was modified 5 months, 3 weeks ago by [viktoriwan](https://wordpress.org/support/users/viktoriwan/).
 * The page I need help with: _[[log in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fmissing-authorization-2%2F%3Foutput_format%3Dmd&locale=en_US)
   to see the link]_

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fmissing-authorization-2%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/image-sizes-controller/assets/icon-128x128.png?rev=2659336)
 * [Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes](https://wordpress.org/plugins/image-sizes-controller/)
 * [Support Threads](https://wordpress.org/support/plugin/image-sizes-controller/)
 * [Active Topics](https://wordpress.org/support/plugin/image-sizes-controller/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/image-sizes-controller/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/image-sizes-controller/reviews/)

 * 0 replies
 * 1 participant
 * Last reply from: [viktoriwan](https://wordpress.org/support/users/viktoriwan/)
 * Last activity: [5 months, 3 weeks ago](https://wordpress.org/support/topic/missing-authorization-2/)
 * Status: not resolved