plugin

Shortpixel Adaptive Images Vulnerabilities

19 known security issues reported for the Shortpixel Adaptive Images WordPress plugin. Most recent disclosed Aug 15, 2026.

11 medium

Running Shortpixel Adaptive Images on your site? Check whether your installed version is affected.

Scan your site free

ShortPixel Adaptive Images <= 3.11.5 - Missing Authorization to Authenticated (Subscriber+) Third-Party Plugin Option Modification via 'causer' Parameter

medium

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attacker...

CVSS:
4.3
Affected:
up to 3.11.5
Fixed in:
3.11.6
Disclosed:
Aug 15, 2026

CVE-2026-15345 on NVD →

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.11.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and...

CVSS:
6.4
Affected:
up to 3.11.3
Fixed in:
3.11.4
Disclosed:
Jun 29, 2026

CVE-2026-57342 on NVD →

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.11.4 - Unauthenticated Arbitrary File Deletion

medium

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 3.11.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which ca...

CVSS:
5.3
Affected:
up to 3.11.4
Fixed in:
3.11.5
Disclosed:
Jun 25, 2026

CVE-2026-56066 on NVD →

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.10.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via API URL

medium

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

CVSS:
4.4
Affected:
up to 3.10.4
Fixed in:
3.10.5
Disclosed:
Aug 1, 2025

CVE-2025-6626 on NVD →

ShortPixel Adaptive Images <= 3.10.0 - Missing Authorization

medium

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handleDeactivation() function in all versions up to, and including, 3.10.0. This makes it possible for authenticated attackers, with Subscriber-level ac...

CVSS:
4.3
Affected:
up to 3.10.0
Fixed in:
3.10.1
Disclosed:
Apr 1, 2025

CVE-2025-30853 on NVD →

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.10.1

unknown

[en] Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ShortPixel Adaptive Images: from n/a through 3.10.0.

Affected:
up to 3.10.1
Fixed in:
3.10.1
Disclosed:
Apr 1, 2025

CVE-2025-30853 on NVD →

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.8.4

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.3.

Affected:
up to 3.8.4
Fixed in:
3.8.4
Disclosed:
May 13, 2024

CVE-2024-35172 on NVD →

ShortPixel Adaptive Images <= 3.8.3 - Authenticated (Admin+) Server-Side Request Forgery

medium

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.8.3 via the is_our_cdn() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating f...

CVSS:
5.5
Affected:
up to 3.8.3
Fixed in:
3.8.4
Disclosed:
May 10, 2024

CVE-2024-35172 on NVD →

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.8.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.3.

Affected:
up to 3.8.4
Fixed in:
3.8.4
Disclosed:
May 10, 2024

CVE-2024-4689 on NVD →

ShortPixel Adaptive Images <= 3.8.3 - Cross-Site Request Forgery

medium

The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.3. This is due to missing or incorrect nonce validation on the import-settings page. This makes it possible for unauthenticated attackers to import settings via a forged request gran...

CVSS:
4.3
Affected:
up to 3.8.3
Fixed in:
3.8.4
Disclosed:
May 9, 2024

CVE-2024-4689 on NVD →

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.8.3

unknown

[en] Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.2.

Affected:
up to 3.8.3
Fixed in:
3.8.3
Disclosed:
Apr 10, 2024

CVE-2024-31230 on NVD →

ShortPixel Adaptive Images <= 3.8.2 - Missing Authorization in activate_ai_handler and deactivate_ai_handler

medium

The ShortPixel Adaptive Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate_ai_handler and deactivate_ai_handler functions in versions up to, and including, 3.8.2. This makes it possible for unauthenticated attackers to activate or deactivate...

CVSS:
5.3
Affected:
up to 3.8.2
Fixed in:
3.8.3
Disclosed:
Apr 2, 2024

CVE-2024-31230 on NVD →

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.7.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin <= 3.7.1 versions.

Affected:
up to 3.7.2
Fixed in:
3.7.2
Disclosed:
Nov 9, 2023

CVE-2023-32512 on NVD →

ShortPixel Adaptive Images <= 3.7.1 - Cross-Site Request Forgery via shortpixel_ai_handle_page_action

medium

The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on the 'shortpixel_ai_handle_page_action' ajax action. This makes it possible for unauthenticated attackers to modify plugin setti...

CVSS:
5.4
Affected:
up to 3.7.2
Fixed in:
3.7.2
Disclosed:
May 8, 2023

CVE-2023-32512 on NVD →

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.6.3

unknown

[en] The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin

Affected:
up to 3.6.3
Fixed in:
3.6.3
Disclosed:
Feb 27, 2023

CVE-2023-0334 on NVD →

ShortPixel Adaptive Images <= 3.6.1 - Reflected Cross-Site Scripting

medium

The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a debugging parameter in versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 3.6.1
Fixed in:
3.6.2
Disclosed:
Feb 2, 2023

CVE-2023-0334 on NVD →

ShortPixel Adaptive Images <= 3.3.1 - Subscriber+ Arbitrary Settings Update

medium

Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.

CVSS:
4.3
Affected:
up to 3.3.1
Fixed in:
3.4.0
Disclosed:
Apr 25, 2022

CVE-2022-29417 on NVD →

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.4.0

unknown

[en] Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.

Affected:
up to 3.4.0
Fixed in:
3.4.0
Disclosed:
Apr 25, 2022

CVE-2022-29417 on NVD →

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] < 3.10.5

unknown
Affected:
up to 3.10.5
Fixed in:
3.10.5

CVE-2025-6626 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database