VYPR

ShortPixel Image Optimizer

by WordPress

CVEs (4)

  • CVE-2024-48043HigOct 17, 2024
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Blind SQL Injection.This issue affects ShortPixel Image Optimizer: from n/a through <= 5.6.3.

  • CVE-2026-39471HigJun 15, 2026
    risk 0.47cvss 7.2epss 0.00

    Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.

  • CVE-2024-48044MedNov 1, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShortPixel Image Optimizer: from n/a through <= 5.6.3.

  • CVE-2025-11378MedOct 18, 2025
    risk 0.28cvss 5.4epss 0.00

    The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes…