VYPR

TinyPNG

by WordPress

CVEs (1)

  • CVE-2026-7311Jul 2, 2026
    risk 0.00cvss epss 0.01

    The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_converted_image_size function in all versions up to, and including, 3.6.13. This makes it possible for…