ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF <= 6.4.3 - Authenticated (Author+) PHP Object Injection
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
Minimum safe version
6.4.4
Update to 6.4.4 or later to address 12 fixable vulnerabilities
ShortPixel Image Optimizer <= 6.4.2 - Authenticated (Editor+) Arbitrary File Read via 'loadFile' Parameter
ShortPixel Image Optimizer <= 6.4.3 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title
CVE-2025-11378
CVE-2024-48044
CVE-2024-48043
ShortPixel Image Optimizer < 5.4.2 - Authenticated(Editor+) PHP Object Injection
WordPress ShortPixel Image Optimizer Plugin < 5.4.2 is vulnerable to PHP Object Injection
ShortPixel Image Optimizer <= 5.4.1 - Authenticated(Editor+) PHP Object Injection
ShortPixel Image Optimizer < 4.22.10 - Reflected Cross-Site Scripting
ShortPixel Image Optimizer <= 4.22.9 - Reflected Cross-Site Scripting
WordPress ShortPixel Image Optimizer plugin <= 4.22.9 - Reflected Cross-Site Scripting (XSS) vulnerability