Squeeze <= 1.7.11 - Authenticated (Author+) Arbitrary File Upload
high
The Squeeze plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 1.7.11. This is due to missing file type validation. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server, which may make r...
- CVSS:
- 8.8
- Affected:
- up to 1.7.11
- Fixed in:
- 1.7.12
- Disclosed:
- Aug 6, 2026
CVE-2026-16985 on NVD →
Squeeze – Image Optimization & Compression, WEBP Conversion [squeeze] <= 1.7.7 (unfixed)
unknown
[en] Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects Squeeze: from n/a through <= 1.7.7.
- Affected:
- up to 1.7.7
- Fix:
- No patched version reported
- Disclosed:
- Mar 13, 2026
CVE-2026-32415 on NVD →
Squeeze <= 1.7.7 - Authenticated (Subscriber+) Directory Traversal
medium
The Squeeze – Image Optimization & Compression, WEBP Conversion plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intende...
- CVSS:
- 4.3
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.8
- Disclosed:
- Feb 25, 2026
CVE-2026-32415 on NVD →
Squeeze <= 1.6 - Authenticated (Admin+) Arbitrary File Upload
high
The Squeeze – Image Optimization & Compression, WebP Conversion plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary f...
- CVSS:
- 7.2
- Affected:
- up to 1.6
- Fixed in:
- 1.6.1
- Disclosed:
- Apr 9, 2025
CVE-2025-31002 on NVD →
Squeeze <= 1.6 - Authenticated (Admin+) Full Path Disclosure
low
The Squeeze – Image Optimization & Compression, WebP Conversion plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The informa...
- CVSS:
- 2.7
- Affected:
- up to 1.6
- Fixed in:
- 1.6.1
- Disclosed:
- Apr 9, 2025
CVE-2025-31003 on NVD →
Squeeze – Image Optimization & Compression, WEBP Conversion [squeeze] < 1.6.1
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze allows Retrieve Embedded Sensitive Data. This issue affects Squeeze: from n/a through 1.6.
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Apr 9, 2025
CVE-2025-31003 on NVD →
Squeeze – Image Optimization & Compression, WEBP Conversion [squeeze] < 1.6.1
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Using Malicious Files. This issue affects Squeeze: from n/a through 1.6.
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Apr 9, 2025
CVE-2025-31002 on NVD →
Squeeze – Image Optimization & Compression, WEBP Conversion [squeeze] < 1.4.1
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Code Injection.This issue affects Squeeze: from n/a through 1.4.
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Jun 21, 2024
CVE-2024-35767 on NVD →
Squeeze <= 1.4 - Authenticated (Admin+) Arbitrary File Upload
critical
The Squeeze plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.4. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may make re...
- CVSS:
- 9.1
- Affected:
- up to 1.4
- Fixed in:
- 1.4.1
- Disclosed:
- Jun 18, 2024
CVE-2024-35767 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database