CVE-2026-15345
- EPSS 0.31%
- Veröffentlicht 16.08.2026 05:27:30
- Zuletzt bearbeitet 20.08.2026 12:48:10
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized t...
CVE-2026-57342
- EPSS 0.22%
- Veröffentlicht 02.07.2026 11:15:04
- Zuletzt bearbeitet 02.07.2026 15:17:07
Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
CVE-2026-56066
- EPSS 0.34%
- Veröffentlicht 26.06.2026 14:52:51
- Zuletzt bearbeitet 26.06.2026 16:16:33
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.
CVE-2025-6626
- EPSS 0.23%
- Veröffentlicht 02.08.2025 07:24:21
- Zuletzt bearbeitet 15.04.2026 00:35:42
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and out...
CVE-2025-30853
- EPSS 0.42%
- Veröffentlicht 01.04.2025 21:15:45
- Zuletzt bearbeitet 23.04.2026 15:27:11
Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.10.0.
CVE-2024-4689
- EPSS 0.25%
- Veröffentlicht 14.05.2024 15:44:25
- Zuletzt bearbeitet 23.04.2026 15:19:52
Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.8.3.
CVE-2024-35172
- EPSS 0.36%
- Veröffentlicht 14.05.2024 15:39:42
- Zuletzt bearbeitet 23.04.2026 15:18:28
Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.8.3.
CVE-2024-31230
- EPSS 0.39%
- Veröffentlicht 10.04.2024 18:15:07
- Zuletzt bearbeitet 28.04.2026 13:16:45
Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.8.2.
CVE-2023-32512
- EPSS 0.31%
- Veröffentlicht 09.11.2023 22:15:10
- Zuletzt bearbeitet 28.04.2026 19:20:28
Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin <= 3.7.1 versions.
CVE-2023-0334
- EPSS 0.88%
- Veröffentlicht 27.02.2023 16:15:12
- Zuletzt bearbeitet 10.03.2025 18:15:25
The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admi...