Impact
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to PHP Object Injection in all releases up to version 6.5.5. The flaw occurs because the plugin deserializes data received from untrusted input, a weakness classified as CWE‑502. Authenticated users with author‑level or higher access can forge a nested JSON payload that is deserialized, allowing them to inject arbitrary PHP objects. Because the plugin itself contains no PHP Object Property (POP) chain that can be abused, this injection does not immediately lead to code execution or data exfiltration within ShortPixel alone. However, if another plugin or theme on the same site defines a malicious POP chain, the injected object can trigger destructive actions such as file deletion, sensitive data retrieval, or arbitrary code execution depending on the chain provided.
Affected Systems
The affected product is the ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF WordPress plugin, versions up to and including 6.5.5. All WordPress sites running any of these versions of the plugin are vulnerable. The CNA lists the vendor shortpixel as the responsible party.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker be authenticated with at least author privilege and that a POP chain exists elsewhere on the site. The likely attack vector is an authenticated user sending a crafted JSON payload to the plugin’s endpoint (inferred from the description). Because no POP chain is present in ShortPixel itself, practical risk depends on the presence of vulnerable plugins or themes that supply a malicious chain.
OpenCVE Enrichment