Description
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFile' AJAX action. This makes it possible for authenticated attackers, with Editor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information such as database credentials and authentication keys.
Published: 2026-02-05
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Read
Action: Patch
AI Analysis

Impact

ShortPixel Image Optimizer versions up to 6.4.2 allow an authenticated attacker with Editor role or higher to read any file on the web server. The vulnerability arises from path‑traversal in an AJAX endpoint that receives a ‘loadFile’ parameter without proper validation or sanitization. An attacker can request sensitive files such as wp-config.php or .env, exposing database credentials, API keys and other secrets. The weakness is classified as CWE‑22, a path traversal flaw that compromises confidentiality of arbitrary server files.

Affected Systems

WordPress sites running the ShortPixel Image Optimizer plugin of any version from the initial release through 6.4.2. The affected product is the ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin provided by ShortPixel.

Risk and Exploitability

The CVSS base score of 4.9 indicates moderate severity; however, the exploitability is low as reflected by an EPSS score under 1%. The flaw is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. The attack vector relies on the user already having Editor‑level WordPress access; an attacker must authenticate and then send a crafted AJAX request targeting the vulnerable ‘loadLogFile’ action. Because of the path‑traversal logic, any file path can be resolved, allowing direct read of the server’s file system within the webroot.

Generated by OpenCVE AI on April 15, 2026 at 21:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ShortPixel Image Optimizer to the latest released version (at least 6.4.3).
  • If an upgrade is not immediately possible, disable or restrict the ‘loadLogFile’ AJAX action for all users, or limit it to administrators only.
  • Configure the server’s file permissions to ensure that WordPress’s web‑accessible directory does not permit reading of sensitive files such as wp-config.php.

Generated by OpenCVE AI on April 15, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 06 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Shortpixel
Shortpixel image Optimizer
Wordpress
Wordpress wordpress
Vendors & Products Shortpixel
Shortpixel image Optimizer
Wordpress
Wordpress wordpress

Thu, 05 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Feb 2026 07:00:00 +0000

Type Values Removed Values Added
Description The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFile' AJAX action. This makes it possible for authenticated attackers, with Editor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information such as database credentials and authentication keys.
Title ShortPixel Image Optimizer <= 6.4.2 - Authenticated (Editor+) Arbitrary File Read via 'loadFile' Parameter
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Shortpixel Image Optimizer
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:33:01.074Z

Reserved: 2026-01-20T18:53:28.652Z

Link: CVE-2026-1246

cve-icon Vulnrichment

Updated: 2026-02-05T14:55:54.196Z

cve-icon NVD

Status : Deferred

Published: 2026-02-05T07:16:17.443

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-1246

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T21:30:13Z

Weaknesses