ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF <= 6.4.3 - Authenticated (Author+) PHP Object Injection
high
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.4.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object....
- CVSS:
- 7.5
- Affected:
- up to 6.4.3
- Fixed in:
- 6.4.4
- Disclosed:
- Apr 20, 2026
CVE-2026-39471 on NVD →
ShortPixel Image Optimizer - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title vulnerability
medium
Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title vulnerability
- CVSS:
- 5.9
- Affected:
- up to 6.4.3
- Fixed in:
- 6.4.4
- Disclosed:
- Mar 27, 2026
ShortPixel Image Optimizer <= 6.4.3 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title
medium
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient output escaping in the getEditorPopup() function and its corresponding media-popup.php template. Specifically, the attac...
- CVSS:
- 5.4
- Affected:
- up to 6.4.3
- Fixed in:
- 6.4.4
- Disclosed:
- Mar 25, 2026
CVE-2026-4335 on NVD →
ShortPixel Image Optimizer <= 6.4.2 - Authenticated (Editor+) Arbitrary File Read via 'loadFile' Parameter
medium
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFile' AJAX action. This makes it possible for authenticated attackers, w...
- CVSS:
- 4.9
- Affected:
- up to 6.4.2
- Fixed in:
- 6.4.3
- Disclosed:
- Feb 4, 2026
CVE-2026-1246 on NVD →
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF [shortpixel-image-optimiser] < 6.3.5
unknown
[en] The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authenticated attackers...
- Affected:
- up to 6.3.5
- Fixed in:
- 6.3.5
- Disclosed:
- Oct 18, 2025
CVE-2025-11378 on NVD →
ShortPixel Image Optimizer <= 6.3.4 - Authenticated (Contributor+) Settings Import/Export
medium
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authenticated attackers, wit...
- CVSS:
- 5.4
- Affected:
- up to 6.3.4
- Fixed in:
- 6.3.5
- Disclosed:
- Oct 17, 2025
CVE-2025-11378 on NVD →
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF [shortpixel-image-optimiser] < 5.6.4
unknown
[en] Missing Authorization vulnerability in ShortPixel – Convert WebP/AVIF & Optimize Images ShortPixel Image Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShortPixel Image Optimizer: from n/a through 5.6.3.
- Affected:
- up to 5.6.4
- Fixed in:
- 5.6.4
- Disclosed:
- Nov 1, 2024
CVE-2024-48044 on NVD →
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF [shortpixel-image-optimiser] < 5.6.4
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPixel Image Optimizer allows Blind SQL Injection.This issue affects ShortPixel Image Optimizer: from n/a through 5.6.3.
- Affected:
- up to 5.6.4
- Fixed in:
- 5.6.4
- Disclosed:
- Oct 17, 2024
CVE-2024-48043 on NVD →
ShortPixel Image Optimizer <= 5.6.3 - Authenticated (Editor+) SQL Injection
medium
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level acce...
- CVSS:
- 4.9
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.4
- Disclosed:
- Oct 13, 2024
CVE-2024-48043 on NVD →
ShortPixel Image Optimizer <= 5.6.3 - Missing Authorization
medium
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several actions in class/Controller/AjaxController.php in versions up to, and including, 5.6.3. This makes it possible for authenticated attackers, with contributor-level access and above, to pe...
- CVSS:
- 4.3
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.4
- Disclosed:
- Oct 13, 2024
CVE-2024-48044 on NVD →
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF [shortpixel-image-optimiser] < 5.4.2
unknown
Update the WordPress ShortPixel Image Optimizer plugin to the latest available version (at least 5.4.2).
Unknown discovered and reported this PHP Object Injection vulnerability in WordPress ShortPixel Image Optimizer Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, de...
- Affected:
- up to 5.4.2
- Fixed in:
- 5.4.2
- Disclosed:
- Sep 15, 2023
ShortPixel Image Optimizer <= 5.4.1 - Authenticated(Editor+) PHP Object Injection
medium
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.4.1 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to inject a PHP Object. No POP chain is present in the vulnerabl...
- CVSS:
- 6.6
- Affected:
- up to 5.4.2
- Fixed in:
- 5.4.2
- Disclosed:
- Sep 14, 2023
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF [shortpixel-image-optimiser] < 5.4.2
unknown
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.4.1 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to inject a PHP Object. No POP chain is present in the vulnerabl...
- Affected:
- up to 5.4.2
- Fixed in:
- 5.4.2
- Disclosed:
- Sep 14, 2023
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF [shortpixel-image-optimiser] < 4.22.10
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress ShortPixel Image Optimizer plugin (versions <= 4.22.9).
Update the WordPress ShortPixel Image Optimizer plugin to the latest available version (at least 4.22.10).
- Affected:
- up to 4.22.10
- Fixed in:
- 4.22.10
- Disclosed:
- Jun 14, 2022
ShortPixel Image Optimizer <= 4.22.9 - Reflected Cross-Site Scripting
medium
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in versions up to, and including, 4.22.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 4.22.9
- Fixed in:
- 4.22.10
- Disclosed:
- Jun 2, 2022
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF [shortpixel-image-optimiser] < 4.22.10
unknown
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in versions up to, and including, 4.22.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- Affected:
- up to 4.22.10
- Fixed in:
- 4.22.10
- Disclosed:
- Jun 2, 2022
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF [shortpixel-image-optimiser] < 4.22.10
unknown
The plugin does not escape a generated URLs before outputting them back in an attribute, leading to Reflected Cross-Site Scripting
- Affected:
- up to 4.22.10
- Fixed in:
- 4.22.10
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF [shortpixel-image-optimiser] < 5.4.2
unknown
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.4.1 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to inject a PHP Object. No POP chain is present in the vulnerabl...
- Affected:
- up to 5.4.2
- Fixed in:
- 5.4.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database