Microsoft Azure Storage for WordPress

Microsoft Azure Storage for WordPress has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Microsoft Azure Storage for WordPress has a vendor fix available, so running the current release closes it.

All of these findings were reported by Jonas Benjamin Friedli. Microsoft Azure Storage for WordPress is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Microsoft Azure Storage for WordPress vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.4CVE-2025-10749

Microsoft Azure Storage for WordPress <= 4.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Media Deletion

Read the full analysis

Vulnerability Records

1 records
Microsoft Azure Storage for WordPress banner
Latestv4.5.2

Microsoft Azure Storage for WordPress

10up

Author

10up

3.9(14)
78/100
Last Updated
2026-06-02 (3mo ago)
Active Installs
2,000+
Downloads
134,797
Requires WP
6.6+
Requires PHP
8.0+
Tested up to
WP 7.0.4
Created
2010-05-20 (17y ago)

This WordPress plugin allows you to use Microsoft Azure Storage Service to host your media and uploads for your WordPress powered website. Microsoft Azure Storage is an effective way to infinitely scale storage of your site and leverage Azure’s global infrastructure. For more details on Microsoft Azure Storage, please visit the Microsoft Azure website. For more details on configuring a Microsoft Azure Storage account and on using the plugin with the Block Editor or Classic Editor, please visit the user guide. Known Issues Storage Account Versions Storage accounts can be created via CLI, classic Azure portal, or the new Azure portal, with varying results. If a Storage account is created with the new Azure portal, authentication will fail, resulting in the inability to view/add containers or files. Creating a Storage account with the Azure CLI should allow the plugin to work with new Storage accounts. Responsive Images in WordPress 4.4 Images uploaded to the Azure Storage service will not automatically receive responsive versions. Images added through the WordPress Media Loader should get automatically converted to responsive images when inserted into a post or page. We are investigating options for full support of responsive images in the plugin.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C