plugin

Shortpixel Image Optimiser Vulnerabilities

18 known security issues reported for the Shortpixel Image Optimiser WordPress plugin. Most recent disclosed Apr 20, 2026.

1 high 8 medium

Running Shortpixel Image Optimiser on your site? Check whether your installed version is affected.

Scan your site free

ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF <= 6.4.3 - Authenticated (Author+) PHP Object Injection

high

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.4.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object....

CVSS:
7.5
Affected:
up to 6.4.3
Fixed in:
6.4.4
Disclosed:
Apr 20, 2026

CVE-2026-39471 on NVD →

ShortPixel Image Optimizer - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title vulnerability

medium

Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title vulnerability

CVSS:
5.9
Affected:
up to 6.4.3
Fixed in:
6.4.4
Disclosed:
Mar 27, 2026

ShortPixel Image Optimizer <= 6.4.3 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title

medium

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient output escaping in the getEditorPopup() function and its corresponding media-popup.php template. Specifically, the attac...

CVSS:
5.4
Affected:
up to 6.4.3
Fixed in:
6.4.4
Disclosed:
Mar 25, 2026

CVE-2026-4335 on NVD →

ShortPixel Image Optimizer <= 6.4.2 - Authenticated (Editor+) Arbitrary File Read via 'loadFile' Parameter

medium

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFile' AJAX action. This makes it possible for authenticated attackers, w...

CVSS:
4.9
Affected:
up to 6.4.2
Fixed in:
6.4.3
Disclosed:
Feb 4, 2026

CVE-2026-1246 on NVD →

ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 6.3.5

unknown

[en] The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authenticated attackers...

Affected:
up to 6.3.5
Fixed in:
6.3.5
Disclosed:
Oct 18, 2025

CVE-2025-11378 on NVD →

ShortPixel Image Optimizer <= 6.3.4 - Authenticated (Contributor+) Settings Import/Export

medium

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authenticated attackers, wit...

CVSS:
5.4
Affected:
up to 6.3.4
Fixed in:
6.3.5
Disclosed:
Oct 17, 2025

CVE-2025-11378 on NVD →

ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4

unknown

[en] Missing Authorization vulnerability in ShortPixel – Convert WebP/AVIF & Optimize Images ShortPixel Image Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShortPixel Image Optimizer: from n/a through 5.6.3.

Affected:
up to 5.6.4
Fixed in:
5.6.4
Disclosed:
Nov 1, 2024

CVE-2024-48044 on NVD →

ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.6.4

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPixel Image Optimizer allows Blind SQL Injection.This issue affects ShortPixel Image Optimizer: from n/a through 5.6.3.

Affected:
up to 5.6.4
Fixed in:
5.6.4
Disclosed:
Oct 17, 2024

CVE-2024-48043 on NVD →

ShortPixel Image Optimizer <= 5.6.3 - Authenticated (Editor+) SQL Injection

medium

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level acce...

CVSS:
4.9
Affected:
up to 5.6.3
Fixed in:
5.6.4
Disclosed:
Oct 13, 2024

CVE-2024-48043 on NVD →

ShortPixel Image Optimizer <= 5.6.3 - Missing Authorization

medium

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several actions in class/Controller/AjaxController.php in versions up to, and including, 5.6.3. This makes it possible for authenticated attackers, with contributor-level access and above, to pe...

CVSS:
4.3
Affected:
up to 5.6.3
Fixed in:
5.6.4
Disclosed:
Oct 13, 2024

CVE-2024-48044 on NVD →

ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.4.2

unknown

Update the WordPress ShortPixel Image Optimizer plugin to the latest available version (at least 5.4.2). Unknown discovered and reported this PHP Object Injection vulnerability in WordPress ShortPixel Image Optimizer Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, de...

Affected:
up to 5.4.2
Fixed in:
5.4.2
Disclosed:
Sep 15, 2023

ShortPixel Image Optimizer <= 5.4.1 - Authenticated(Editor+) PHP Object Injection

medium

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.4.1 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to inject a PHP Object. No POP chain is present in the vulnerabl...

CVSS:
6.6
Affected:
up to 5.4.2
Fixed in:
5.4.2
Disclosed:
Sep 14, 2023

ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.4.2

unknown

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.4.1 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to inject a PHP Object. No POP chain is present in the vulnerabl...

Affected:
up to 5.4.2
Fixed in:
5.4.2
Disclosed:
Sep 14, 2023

ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 4.22.10

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress ShortPixel Image Optimizer plugin (versions <= 4.22.9). Update the WordPress ShortPixel Image Optimizer plugin to the latest available version (at least 4.22.10).

Affected:
up to 4.22.10
Fixed in:
4.22.10
Disclosed:
Jun 14, 2022

ShortPixel Image Optimizer <= 4.22.9 - Reflected Cross-Site Scripting

medium

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in versions up to, and including, 4.22.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 4.22.9
Fixed in:
4.22.10
Disclosed:
Jun 2, 2022

ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 4.22.10

unknown

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in versions up to, and including, 4.22.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

Affected:
up to 4.22.10
Fixed in:
4.22.10
Disclosed:
Jun 2, 2022

ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 4.22.10

unknown

The plugin does not escape a generated URLs before outputting them back in an attribute, leading to Reflected Cross-Site Scripting

Affected:
up to 4.22.10
Fixed in:
4.22.10

ShortPixel Image Optimizer &#8211; Optimize Images, Convert WebP &amp; AVIF [shortpixel-image-optimiser] < 5.4.2

unknown

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.4.1 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to inject a PHP Object. No POP chain is present in the vulnerabl...

Affected:
up to 5.4.2
Fixed in:
5.4.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database