critical · CVSS v3 8.8
CVE-2026-17086
The ShortPixel Image Optimizer plugin for WordPress contains a PHP Object Injection vulnerability in versions up to and including 6.5.5. It
Overview
The ShortPixel Image Optimizer plugin for WordPress contains a PHP Object Injection vulnerability in versions up to and including 6.5.5. It arises from the unsafe deserialization of untrusted input accessible to authenticated users with author-level privileges and above. While no native POP chain exists in the plugin itself, the presence of a compatible gadget chain from another theme or plugin could enable arbitrary file deletion, data retrieval, or code execution.
Description
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Impact
This vulnerability impacts WordPress sites running vulnerable versions of the ShortPixel Image Optimizer alongside other third-party components containing a valid POP chain. If exploited in such environments, the integrity and confidentiality of the system could be severely compromised through arbitrary file deletion, sensitive data exposure, or remote code execution. Authenticated attackers with author-level access or higher represent the primary internal threat actor vector.
Remediation
Update the ShortPixel Image Optimizer plugin to a patched version beyond 6.5.5 as soon as it becomes available by the vendor. Audit installed WordPress plugins and themes to identify and remove any components containing known insecure PHP object deserialization gadget chains. Restrict author-level and higher user roles to trusted individuals to limit the potential misuse of authenticated features.
Risk context
This vulnerability is classified as critical with a CVSS v3 score of 8.8, reflecting severe potential impact if combined with external gadget chains. Defenders should prioritize patching, especially on multi-author WordPress installations where low-privilege administrative access is widely distributed.
Affected products
- ShortPixel ShortPixel Image Optimizer
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —