Impact
The vulnerability is a PHP Object Injection flaw in the ShortPixel Image Optimizer WordPress plugin versions 6.5.5 and earlier. An attacker able to control serialized data passed through the plugin can cause the plugin to instantiate arbitrary PHP objects, potentially leading to code execution or other malicious behavior. The weakness is classified as CWE‑502.
Affected Systems
ShortPixel Image Optimizer plugin for WordPress, versions up to and including 6.5.5. Any WordPress installation that has this plugin installed and has not applied the 6.5.6 update is at risk.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that large‑scale exploitation has not yet been observed. The likely attack vector is via the plugin’s API or configuration interface, which requires an authenticated user with subscriber-level access to the plugin. If an attacker can supply crafted serialized data through the plugin, arbitrary objects can be instantiated, leading to remote code execution. Verification of a current patch is required before accepting this vulnerability as mitigated.
OpenCVE Enrichment