Extension WordPress
Vulnérabilités ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
Cette page rassemble les failles publiées pour ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
8 fiches
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF <= 6.4.3 – Authenticated (Author+) PHP Object Injection
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.4.3 via deserialization of untrusted input. This makes it possible for authenticated…
*-6.4.3
6.4.4
20/04/2026
ShortPixel Image Optimizer <= 6.4.3 – Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient output escaping in the getEditorPopup() function and its…
*-6.4.3
6.4.4
25/03/2026
ShortPixel Image Optimizer <= 6.4.2 – Authenticated (Editor+) Arbitrary File Read via 'loadFile' Parameter
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFile'…
*-6.4.2
6.4.3
04/02/2026
ShortPixel Image Optimizer <= 6.3.4 – Authenticated (Contributor+) Settings Import/Export
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and…
*-6.3.4
6.3.5
17/10/2025
ShortPixel Image Optimizer <= 5.6.3 – Authenticated (Editor+) SQL Injection
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
*-5.6.3
5.6.4
13/10/2024
ShortPixel Image Optimizer <= 5.6.3 – Missing Authorization
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several actions in class/Controller/AjaxController.php in versions up to, and including, 5.6.3. This makes it possible for authenticated attackers, with…
*-5.6.3
5.6.4
13/10/2024
ShortPixel Image Optimizer <= 5.4.1 – Authenticated(Editor+) PHP Object Injection
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.4.1 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to…
[*, 5.4.2)
5.4.2
14/09/2023
ShortPixel Image Optimizer <= 4.22.9 – Reflected Cross-Site Scripting
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in versions up to, and including, 4.22.9. This makes it possible…
*-4.22.9
4.22.10
02/06/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.