CVE-2026-5821 affects Image Optimizer through version 1.7.4 and allows an authenticated Author to cause arbitrary file deletion through attachment backup metadata. The plugin trusts stored backup paths during attachment cleanup without checking that they belong to the expected image backups. Files writable by the web server may be removed, causing data loss, denial of service, or weakened site protection. The issue is fixed in version 1.7.5.
| CVE | CVE-2026-5821 |
| Plugin Version | Image Optimizer <= 1.7.4, fixed in 1.7.5 |
| All Time | 16 277 489 |
| Active installations | 1 000 000+ |
| Publicly Published | July 1, 2026 |
| Last Updated | July 2, 2026 |
| Researcher | Dmitrii Ignatyev |
| CWE | CWE-73 – External Control of File Name or Path |
| PoC | Yes |
| Exploit | No |
| Reference | https://www.cve.org/CVERecord?id=CVE-2026-5821 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/image-optimization/image-optimizer-174-authenticated-author-arbitrary-file-deletion-via-post-meta-field-injection |
| Plugin Security Certification by CleanTalk | ![]() |
| Logo of the plugin | ![]() |
PSC by CleantalkJoin the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.
Timeline
| March 2, 2026 | Plugin testing and vulnerability detection in Image Optimizer 1.7.3 were completed. |
| March 2, 2026 | The vulnerability report was sent with the PoC and technical description. |
| July 1, 2026 | Wordfence publicly published the advisory for CVE-2026-5821. |
| July 2, 2026 | The CVE-2026-5821 record was published in the CVE Program registry. |
Discovery of the Vulnerability
The supplied research notes describe testing of Image Optimizer 1.7.3. The plugin keeps image backup information in the attachment post meta field image_optimizer_metadata. This data includes filesystem paths for backup copies. Because that metadata can be influenced by a user who controls the attachment, it cannot serve as proof that a path is safe to delete.
The vulnerable cleanup path runs when an attachment is permanently removed. The delete_attachment hook reaches Image_Backup::remove(), which processes stored backup paths and passes them to File_System::delete(). The missing check is the connection between each candidate path and the attachment’s legitimate backup files. Wordfence lists versions through 1.7.4 as affected and identifies 1.7.5 as the patched release.
Understanding of Arbitrary File Deletion attacks
Arbitrary file deletion occurs when untrusted data determines which filesystem object an application removes. Access to an attachment should grant control over that attachment, its image sizes, and its verified backups. It should not grant control over unrelated files merely because a plugin can access them.
The relevant role is usually Author, with permission to upload media, edit their own attachment, and delete it. A valid login and an attachment edit nonce do not validate a filesystem path. The practical reach remains limited by the web server account’s permissions, but removal of other media or writable site files can still interrupt service. Removal of a protective file may also weaken an existing security control. The reported issue does not by itself establish arbitrary file reading or remote code execution.
Exploiting the Arbitrary File Deletion Vulnerability
The researcher supplied an authenticated local PoC against version 1.7.3. The summary below preserves the tested role and the failed security boundary. Session cookies, nonce values, the replayable HTTP request, and the filesystem deletion target are omitted.
POC:
POC: Researcher-supplied local test summary Tested plugin - Image Optimizer 1.7.3 Account - authenticated Author with control over their own attachment Affected boundary - attachment backup metadata and filesystem cleanup Reported result - cleanup accepts a path outside the expected backup set Expected result - reject any path not belonging to this attachment HTTP request, session credentials, and deletion target omitted. This example documents the finding and does not perform file deletion.____
The reported outcome follows from trusting stored backup locations during cleanup. A secure implementation rejects a candidate outside the permitted backup set before it reaches the deletion primitive. This article records the supplied observation and does not claim a new runtime reproduction.
Recommendations for Improved Security
Update Image Optimizer to version 1.7.5 or a newer patched release. The current WordPress.org release checked for this article is 1.7.7. Maintain tested backups and review unexpected file removals on sites that ran an affected version. Until the update is applied, limit media management access to trusted accounts.
Developers should validate backup metadata as untrusted input and derive expected backup locations from trusted attachment data. Resolve candidate paths, require containment within the permitted backup directory, and verify that each candidate belongs to the attachment being removed. Handle symlinks and path boundaries explicitly. Reject malformed metadata and use filesystem permissions that prevent the web server from deleting unrelated site files. Regression checks should cover valid backups, unrelated paths, malformed records, and symlink escapes.
Applying the fix for CVE-2026-5821 restores the boundary between an Author’s media attachment and unrelated files on the server. Backup cleanup needs to validate ownership and location before any deletion.
#WordPressSecurity #ArbitraryFileDeletion #ImageOptimizer #PluginSecurity #WebsiteSafety #StayProtected
Use CleanTalk solutions to improve the security of your website

