plugin

Wp Smushit Vulnerabilities

15 known security issues reported for the Wp Smushit WordPress plugin. Most recent disclosed Mar 29, 2025.

1 critical 1 high 3 medium 1 low

Running Wp Smushit on your site? Check whether your installed version is affected.

Scan your site free

Smush Image Compression and Optimization <= 3.17.0 - Authenticated (Admin+) Directory Traversal

low

The Smush Image Optimization – Optimize Images | Compress & Lazy Load Images | Convert WebP & AVIF | Image CDN plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.17.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to perform...

CVSS:
2.7
Affected:
up to 3.17.0
Fixed in:
3.17.1
Disclosed:
Mar 29, 2025

CVE-2025-22288 on NVD →

Smush Image Optimization – Optimize Images | Compress &amp; Lazy Load Images | Convert WebP &amp; AVIF | Image CDN [wp-smushit] < 3.16.5

unknown

[en] The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability check on the delete_resmush_list() function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to delete the resmush list for Nextgen or the Media L...

Affected:
up to 3.16.5
Fixed in:
3.16.5
Disclosed:
Jun 21, 2024

CVE-2023-3352 on NVD →

Smush – Lazy Load Images, Optimize & Compress Images <= 3.16.4 - Missing Authorization to Resmush List Deletion

medium

The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability check on the delete_resmush_list() function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to delete the resmush list for Nextgen or the Media Librar...

CVSS:
4.3
Affected:
up to 3.16.4
Fixed in:
3.16.5
Disclosed:
Jun 20, 2024

CVE-2023-3352 on NVD →

Smush Image Optimization – Optimize Images | Compress &amp; Lazy Load Images | Convert WebP &amp; AVIF | Image CDN [wp-smushit] < 3.9.9

unknown

[en] The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back in an admin page when uploading a malicious preset configuration, leading to a Reflected Cross-Site Scripting. For the attack to be successful, an attacker would need an admin to upload a malici...

Affected:
up to 3.9.9
Fixed in:
3.9.9
Disclosed:
May 30, 2022

CVE-2022-1009 on NVD →

Smush – Lazy Load Images, Optimize & Compress Images <= 3.9.8 - Cross-Site Scripting

medium

The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'name' and 'description' parameters in versions up to, and including, 3.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...

CVSS:
4.4
Affected:
up to 3.9.8
Fixed in:
3.9.9
Disclosed:
May 3, 2022

CVE-2022-1009 on NVD →

Smush – Lazy Load Images, Optimize & Compress Images <= 2.9.1 - Cross-Site Scripting

critical

The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to Cross-Site Scripting leading in versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject malicious web scripts into the application.

CVSS:
9.8
Affected:
up to 2.9.1
Fixed in:
3.0.0
Disclosed:
Dec 10, 2018

Smush – Lazy Load Images, Optimize & Compress Images <= 3.0.0 - Authenticated PHAR Deserialization

high

The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 3.0.0. This makes it possible for authenticated attackers to call files using a PHAR wrapper that will deserialize the data and cal...

CVSS:
8.8
Affected:
up to 3.0.0
Fixed in:
3.0.1
Disclosed:
Dec 10, 2018

Smush Image Optimization – Optimize Images | Compress &amp; Lazy Load Images | Convert WebP &amp; AVIF | Image CDN [wp-smushit] < 3.0.0

unknown

Authenticated XSS & Phar Deserialization vulnerabilities found by RIPS Technologies in WordPress Smush Image Compression and Optimization plugin (versions <= 2.9.1).

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Dec 10, 2018

Smush Image Optimization – Optimize Images | Compress &amp; Lazy Load Images | Convert WebP &amp; AVIF | Image CDN [wp-smushit] < 3.0.1

unknown

The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 3.0.0. This makes it possible for authenticated attackers to call files using a PHAR wrapper that will deserialize the data and cal...

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Dec 10, 2018

Smush Image Optimization – Optimize Images | Compress &amp; Lazy Load Images | Convert WebP &amp; AVIF | Image CDN [wp-smushit] < 3.0.0

unknown

The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to Cross-Site Scripting leading in versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject malicious web scripts into the application.

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Dec 10, 2018

Smush Image Optimization – Optimize Images | Compress &amp; Lazy Load Images | Convert WebP &amp; AVIF | Image CDN [wp-smushit] < 2.7.6

unknown

File Traversal vulnerability found by Ricardo Sánchez in WordPress Smush Image Compression and Optimization plugin (versions <=2.7.5).

Affected:
up to 2.7.6
Fixed in:
2.7.6
Disclosed:
Oct 9, 2017

Smush Image Optimization – Optimize Images | Compress &amp; Lazy Load Images | Convert WebP &amp; AVIF | Image CDN [wp-smushit] < 2.7.6

unknown

[en] The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal.

Affected:
up to 2.7.6
Fixed in:
2.7.6
Disclosed:
Oct 6, 2017

CVE-2017-15079 on NVD →

Smush – Lazy Load Images, Optimize & Compress Images <= 2.7.5 - Directory Traversal

medium

The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal.

CVSS:
5.3
Affected:
up to 2.7.5
Fixed in:
2.7.6
Disclosed:
Sep 21, 2017

CVE-2017-15079 on NVD →

Smush Image Optimization – Optimize Images | Compress &amp; Lazy Load Images | Convert WebP &amp; AVIF | Image CDN [wp-smushit] < 3.9.9

unknown

The Smush &ndash; Lazy Load Images, Optimize &amp; Compress Images WordPress plugin was affected by an Authenticated Phar Deserialization security vulnerability.

Affected:
up to 3.9.9
Fixed in:
3.9.9

Smush Image Optimization – Optimize Images | Compress &amp; Lazy Load Images | Convert WebP &amp; AVIF | Image CDN [wp-smushit] < 3.17.1

unknown
Affected:
up to 3.17.1
Fixed in:
3.17.1

CVE-2025-22288 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database