Impact
The ShortPixel Adaptive Images plugin for WordPress allows authenticated users with subscriber-level or higher privileges to modify configuration options of the plugin itself and other installed third‑party optimizers through the 'causer' parameter, because the plugin fails to enforce proper authorization. This vulnerability does not let attackers execute arbitrary code, but it permits tampering with settings of ShortPixel Image Optimizer, Autoptimize, WP Rocket, Imagify, LiteSpeed Cache, including the plugin's own API key and account binding. As a result, an attacker could disrupt site performance, redirect traffic, or compromise account access by altering API keys.
Affected Systems
The flaw exists in all ShortPixel Adaptive Images releases up to and including 3.11.5. Any WordPress site running this plugin, coupled with the presence of one or more of the following third‑party optimizers—ShortPixel Image Optimizer, Autoptimize, WP Rocket, Imagify, LiteSpeed Cache—is vulnerable. No other products or versions are listed as affected.
Risk and Exploitability
The CVSS v3.1 base score is 4.3, reflecting a moderate impact and requires authenticated access to exploit. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker gains only configuration change privileges; no remote code execution or data exfiltration is possible. Prevention hinges on disabling the 'causer' parameter usage or ensuring the plugin is upgraded to a version that restores proper authorization checks.
OpenCVE Enrichment