CVE-2026-5821 affects Image Optimizer through version 1.7.4 and allows an authenticated Author to cause arbitrary file deletion through attachment backup metadata. The plugin trusts stored backup paths during attachment cleanup without checking that they belong to the expected image backups. Files writable by the web server may be removed, causing data loss, denial of service, or weakened site protection. The issue is fixed in version 1.7.5.

CVECVE-2026-5821
Plugin VersionImage Optimizer <= 1.7.4, fixed in 1.7.5
All Time16 277 489
Active installations1 000 000+
Publicly PublishedJuly 1, 2026
Last UpdatedJuly 2, 2026
ResearcherDmitrii Ignatyev
CWECWE-73 – External Control of File Name or Path
PoCYes
ExploitNo
Referencehttps://www.cve.org/CVERecord?id=CVE-2026-5821
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/image-optimization/image-optimizer-174-authenticated-author-arbitrary-file-deletion-via-post-meta-field-injection
Plugin Security Certification by CleanTalk
Logo of the pluginImage Optimizer plugin logo

Join the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.

PSC by Cleantalk

Timeline

March 2, 2026Plugin testing and vulnerability detection in Image Optimizer 1.7.3 were completed.
March 2, 2026The vulnerability report was sent with the PoC and technical description.
July 1, 2026Wordfence publicly published the advisory for CVE-2026-5821.
July 2, 2026The CVE-2026-5821 record was published in the CVE Program registry.

Discovery of the Vulnerability

The supplied research notes describe testing of Image Optimizer 1.7.3. The plugin keeps image backup information in the attachment post meta field image_optimizer_metadata. This data includes filesystem paths for backup copies. Because that metadata can be influenced by a user who controls the attachment, it cannot serve as proof that a path is safe to delete.

The vulnerable cleanup path runs when an attachment is permanently removed. The delete_attachment hook reaches Image_Backup::remove(), which processes stored backup paths and passes them to File_System::delete(). The missing check is the connection between each candidate path and the attachment’s legitimate backup files. Wordfence lists versions through 1.7.4 as affected and identifies 1.7.5 as the patched release.

Understanding of Arbitrary File Deletion attacks

Arbitrary file deletion occurs when untrusted data determines which filesystem object an application removes. Access to an attachment should grant control over that attachment, its image sizes, and its verified backups. It should not grant control over unrelated files merely because a plugin can access them.

The relevant role is usually Author, with permission to upload media, edit their own attachment, and delete it. A valid login and an attachment edit nonce do not validate a filesystem path. The practical reach remains limited by the web server account’s permissions, but removal of other media or writable site files can still interrupt service. Removal of a protective file may also weaken an existing security control. The reported issue does not by itself establish arbitrary file reading or remote code execution.

Exploiting the Arbitrary File Deletion Vulnerability

The researcher supplied an authenticated local PoC against version 1.7.3. The summary below preserves the tested role and the failed security boundary. Session cookies, nonce values, the replayable HTTP request, and the filesystem deletion target are omitted.

POC:

POC:
Researcher-supplied local test summary

Tested plugin - Image Optimizer 1.7.3
Account - authenticated Author with control over their own attachment
Affected boundary - attachment backup metadata and filesystem cleanup
Reported result - cleanup accepts a path outside the expected backup set
Expected result - reject any path not belonging to this attachment

HTTP request, session credentials, and deletion target omitted.
This example documents the finding and does not perform file deletion.

____

The reported outcome follows from trusting stored backup locations during cleanup. A secure implementation rejects a candidate outside the permitted backup set before it reaches the deletion primitive. This article records the supplied observation and does not claim a new runtime reproduction.

Recommendations for Improved Security

Update Image Optimizer to version 1.7.5 or a newer patched release. The current WordPress.org release checked for this article is 1.7.7. Maintain tested backups and review unexpected file removals on sites that ran an affected version. Until the update is applied, limit media management access to trusted accounts.

Developers should validate backup metadata as untrusted input and derive expected backup locations from trusted attachment data. Resolve candidate paths, require containment within the permitted backup directory, and verify that each candidate belongs to the attachment being removed. Handle symlinks and path boundaries explicitly. Reject malformed metadata and use filesystem permissions that prevent the web server from deleting unrelated site files. Regression checks should cover valid backups, unrelated paths, malformed records, and symlink escapes.

Applying the fix for CVE-2026-5821 restores the boundary between an Author’s media attachment and unrelated files on the server. Backup cleanup needs to validate ownership and location before any deletion.

#WordPressSecurity #ArbitraryFileDeletion #ImageOptimizer #PluginSecurity #WebsiteSafety #StayProtected

Use CleanTalk solutions to improve the security of your website

CVE-2026-5821 – Image Optimizer – Author+ File Deletion – POC

Dmitrii I

Pentester with 5 years of hands-on experience securing WordPress and web applications, holding OSWE, OSEP, OSCP, and OSWP certifications. Author of 450 published CVEs, including 35 disclosed within the last month. Specializes in discovering and validating high-impact vulnerabilities in WordPress plugins/themes / Custom WEB applications and delivering actionable remediation guidance to harden production sites.

Visit Author's Website

See all posts by dmitrii-ignatyev

Leave a Reply

Your email address will not be published. Required fields are marked *