Extension WordPress

Vulnérabilités ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

Cette page rassemble les failles publiées pour ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

8 fiches

CVE-2026-39471 Élevée · 7,5
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF <= 6.4.3 – Authenticated (Author+) PHP Object Injection

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.4.3 via deserialization of untrusted input. This makes it possible for authenticated…

Versions affectées

*-6.4.3

Correctif

6.4.4

Publication

20/04/2026

CVE-2026-4335 Moyenne · 5,4
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

ShortPixel Image Optimizer <= 6.4.3 – Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient output escaping in the getEditorPopup() function and its…

Versions affectées

*-6.4.3

Correctif

6.4.4

Publication

25/03/2026

CVE-2026-1246 Moyenne · 4,9
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

ShortPixel Image Optimizer <= 6.4.2 – Authenticated (Editor+) Arbitrary File Read via 'loadFile' Parameter

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFile'…

Versions affectées

*-6.4.2

Correctif

6.4.3

Publication

04/02/2026

CVE-2025-11378 Moyenne · 5,4
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

ShortPixel Image Optimizer <= 6.3.4 – Authenticated (Contributor+) Settings Import/Export

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and…

Versions affectées

*-6.3.4

Correctif

6.3.5

Publication

17/10/2025

CVE-2024-48043 Moyenne · 4,9
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

ShortPixel Image Optimizer <= 5.6.3 – Authenticated (Editor+) SQL Injection

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-5.6.3

Correctif

5.6.4

Publication

13/10/2024

CVE-2024-48044 Moyenne · 4,3
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

ShortPixel Image Optimizer <= 5.6.3 – Missing Authorization

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several actions in class/Controller/AjaxController.php in versions up to, and including, 5.6.3. This makes it possible for authenticated attackers, with…

Versions affectées

*-5.6.3

Correctif

5.6.4

Publication

13/10/2024

Vulnérabilité Moyenne · 6,6
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

ShortPixel Image Optimizer <= 5.4.1 – Authenticated(Editor+) PHP Object Injection

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.4.1 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to…

Versions affectées

[*, 5.4.2)

Correctif

5.4.2

Publication

14/09/2023

Vulnérabilité Moyenne · 6,1
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF

ShortPixel Image Optimizer <= 4.22.9 – Reflected Cross-Site Scripting

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in versions up to, and including, 4.22.9. This makes it possible…

Versions affectées

*-4.22.9

Correctif

4.22.10

Publication

02/06/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités