Extension WordPress
Vulnérabilités ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization
Cette page rassemble les failles publiées pour ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization
10 fiches
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.11.3 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.3 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.11.3
3.11.4
29/06/2026
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.11.4 – Unauthenticated Arbitrary File Deletion
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 3.11.4. This makes it possible for…
*-3.11.4
3.11.5
25/06/2026
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.10.4 – Authenticated (Administrator+) Stored Cross-Site Scripting via API URL
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and…
*-3.10.4
3.10.5
01/08/2025
ShortPixel Adaptive Images <= 3.10.0 – Missing Authorization
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handleDeactivation() function in all versions up to, and including, 3.10.0. This makes…
*-3.10.0
3.10.1
01/04/2025
ShortPixel Adaptive Images <= 3.8.3 – Authenticated (Admin+) Server-Side Request Forgery
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.8.3 via the is_our_cdn() function. This makes it possible for unauthenticated attackers…
*-3.8.3
3.8.4
10/05/2024
ShortPixel Adaptive Images <= 3.8.3 – Cross-Site Request Forgery
The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.3. This is due to missing or incorrect nonce validation on the import-settings page. This makes it possible…
*-3.8.3
3.8.4
09/05/2024
ShortPixel Adaptive Images <= 3.8.2 – Missing Authorization in activate_ai_handler and deactivate_ai_handler
The ShortPixel Adaptive Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate_ai_handler and deactivate_ai_handler functions in versions up to, and including, 3.8.2. This makes it possible for…
*-3.8.2
3.8.3
02/04/2024
ShortPixel Adaptive Images <= 3.7.1 – Cross-Site Request Forgery via shortpixel_ai_handle_page_action
The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on the 'shortpixel_ai_handle_page_action' ajax action. This makes it possible…
[*, 3.7.2)
3.7.2
08/05/2023
ShortPixel Adaptive Images <= 3.6.1 – Reflected Cross-Site Scripting
The ShortPixel Adaptive Images plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a debugging parameter in versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-3.6.1
3.6.2
02/02/2023
ShortPixel Adaptive Images <= 3.3.1 – Subscriber+ Arbitrary Settings Update
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin
*-3.3.1
3.4.0
25/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.