CVE-2026-4335
- EPSS 0.04%
- Veröffentlicht 26.03.2026 02:25:20
- Zuletzt bearbeitet 30.03.2026 13:26:50
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient output escaping in the getEditorPopup() function a...
CVE-2026-1246
- EPSS 0.06%
- Veröffentlicht 05.02.2026 06:47:41
- Zuletzt bearbeitet 15.04.2026 00:35:42
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFi...
CVE-2025-11378
- EPSS 0.05%
- Veröffentlicht 18.10.2025 03:33:23
- Zuletzt bearbeitet 15.04.2026 00:35:42
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and inc...
CVE-2024-48044
- EPSS 0.63%
- Veröffentlicht 01.11.2024 15:15:56
- Zuletzt bearbeitet 01.04.2026 16:18:24
Missing Authorization vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShortPixel Image Optimizer: from n/a through <= 5.6.3.
CVE-2024-48043
- EPSS 0.15%
- Veröffentlicht 17.10.2024 12:15:02
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Blind SQL Injection.This issue affects ShortPixel Image Optimizer: from n/a ...