Description
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: PHP Object Injection
Action: Apply Patch
AI Analysis

Impact

The ShortPixel Image Optimizer plugin for WordPress is vulnerable to PHP Object Injection in all releases up to version 6.5.5. The flaw occurs because the plugin deserializes data received from untrusted input, a weakness classified as CWE‑502. Authenticated users with author‑level or higher access can forge a nested JSON payload that is deserialized, allowing them to inject arbitrary PHP objects. Because the plugin itself contains no PHP Object Property (POP) chain that can be abused, this injection does not immediately lead to code execution or data exfiltration within ShortPixel alone. However, if another plugin or theme on the same site defines a malicious POP chain, the injected object can trigger destructive actions such as file deletion, sensitive data retrieval, or arbitrary code execution depending on the chain provided.

Affected Systems

The affected product is the ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF WordPress plugin, versions up to and including 6.5.5. All WordPress sites running any of these versions of the plugin are vulnerable. The CNA lists the vendor shortpixel as the responsible party.

Risk and Exploitability

The CVSS base score of 8.8 indicates high severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker be authenticated with at least author privilege and that a POP chain exists elsewhere on the site. The likely attack vector is an authenticated user sending a crafted JSON payload to the plugin’s endpoint (inferred from the description). Because no POP chain is present in ShortPixel itself, practical risk depends on the presence of vulnerable plugins or themes that supply a malicious chain.

Generated by OpenCVE AI on September 19, 2026 at 21:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ShortPixel to version 6.5.6 or later where deserialization is sanitized.
  • Remove or patch any additional plugins or themes that provide a POP chain before using ShortPixel.
  • Restrict author‑level and higher user privileges and enforce least privilege policies to limit the ability to submit malicious payloads.
  • Monitor site logs for suspicious object injection attempts.

Generated by OpenCVE AI on September 19, 2026 at 21:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.1/build/shortpixel/replacer2/src/Replacer.php#L259 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.1/build/shortpixel/replacer2/src/Replacer.php#L402 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.1/build/shortpixel/replacer2/src/Replacer.php#L425 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.1/build/shortpixel/replacer2/src/Replacer.php#L429 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.1/build/shortpixel/replacer2/src/Replacer.php#L446 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.1/class/Controller/Optimizer/OptimizeAiController.php#L598 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.4/build/shortpixel/replacer2/src/Replacer.php#L259 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.4/build/shortpixel/replacer2/src/Replacer.php#L402 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.4/build/shortpixel/replacer2/src/Replacer.php#L425 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.4/build/shortpixel/replacer2/src/Replacer.php#L429 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.4/build/shortpixel/replacer2/src/Replacer.php#L446 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/shortpixel-image-optimiser/tags/6.5.4/class/Controller/Optimizer/OptimizeAiController.php#L598 cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?reponame=&old=3688579%40shortpixel-image-optimiser&new=3688579%40shortpixel-image-optimiser cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/89ef2ee1-2bec-459f-9a85-c260cbb129ca?source=cve cve-icon cve-icon
History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Shortpixel
Shortpixel shortpixel Image Optimizer – Optimize Images, Convert Webp & Avif
Wordpress
Wordpress wordpress
Vendors & Products Shortpixel
Shortpixel shortpixel Image Optimizer – Optimize Images, Convert Webp & Avif
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Title ShortPixel Image Optimizer <= 6.5.5 - Authenticated (Author+) PHP Object Injection via Nested JSON Post Content
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Shortpixel Shortpixel Image Optimizer – Optimize Images, Convert Webp & Avif
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T14:31:42.846Z

Reserved: 2026-07-24T14:41:24.795Z

Link: CVE-2026-17086

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:40.713Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T04:17:28.900

Modified: 2026-09-18T15:17:06.153

Link: CVE-2026-17086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:45:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data