Description
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify configuration options of third-party plugins including ShortPixel Image Optimizer, Autoptimize, WP Rocket, Imagify, and LiteSpeed Cache, as well as the plugin's own API key and account binding. Exploitation requires the respective third-party plugins to be installed, as the impact against those plugins' settings is only reachable when those plugins are present.
Published: 2026-08-16
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ShortPixel Adaptive Images plugin for WordPress allows authenticated users with subscriber-level or higher privileges to modify configuration options of the plugin itself and other installed third‑party optimizers through the 'causer' parameter, because the plugin fails to enforce proper authorization. This vulnerability does not let attackers execute arbitrary code, but it permits tampering with settings of ShortPixel Image Optimizer, Autoptimize, WP Rocket, Imagify, LiteSpeed Cache, including the plugin's own API key and account binding. As a result, an attacker could disrupt site performance, redirect traffic, or compromise account access by altering API keys.

Affected Systems

The flaw exists in all ShortPixel Adaptive Images releases up to and including 3.11.5. Any WordPress site running this plugin, coupled with the presence of one or more of the following third‑party optimizers—ShortPixel Image Optimizer, Autoptimize, WP Rocket, Imagify, LiteSpeed Cache—is vulnerable. No other products or versions are listed as affected.

Risk and Exploitability

The CVSS v3.1 base score is 4.3, reflecting a moderate impact and requires authenticated access to exploit. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker gains only configuration change privileges; no remote code execution or data exfiltration is possible. Prevention hinges on disabling the 'causer' parameter usage or ensuring the plugin is upgraded to a version that restores proper authorization checks.

Generated by OpenCVE AI on August 16, 2026 at 06:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ShortPixel Adaptive Images to a patched release (e.g., 3.11.6 or later) to eliminate the flawed authorization check.
  • Disable or uninstall unnecessary third‑party image‑optimization plugins, or restrict their use to trusted users only.
  • Revise WordPress role permissions so that only administrators have the capability to modify plugin settings; downgrade subscriber roles where possible.

Generated by OpenCVE AI on August 16, 2026 at 06:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 16 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Description The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify configuration options of third-party plugins including ShortPixel Image Optimizer, Autoptimize, WP Rocket, Imagify, and LiteSpeed Cache, as well as the plugin's own API key and account binding. Exploitation requires the respective third-party plugins to be installed, as the impact against those plugins' settings is only reachable when those plugins are present.
Title ShortPixel Adaptive Images <= 3.11.5 - Missing Authorization to Authenticated (Subscriber+) Third-Party Plugin Option Modification via 'causer' Parameter
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-16T05:27:30.700Z

Reserved: 2026-07-09T20:25:55.728Z

Link: CVE-2026-15345

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-16T06:16:50.493

Modified: 2026-08-16T06:16:50.493

Link: CVE-2026-15345

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-16T06:30:04Z

Weaknesses