cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forshortpixel-adaptive-images shortpixel-adaptive-images

Direction: ascending
Jun 06, 2024

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization # CVE-2024-35172

CVE, Research URL

CVE-2024-35172

Date
May 14, 2024
Research Description
Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.3.
Affected versions
Min -, max -.
Status
vulnerable

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization # CVE-2022-29417

CVE, Research URL

CVE-2022-29417

Date
Apr 25, 2022
Research Description
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.
Affected versions
Min -, max -.
Status
vulnerable

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization # CVE-2023-0334

CVE, Research URL

CVE-2023-0334

Date
Feb 27, 2023
Research Description
The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin
Affected versions
Min -, max -.
Status
vulnerable

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization # CVE-2023-32512

CVE, Research URL

CVE-2023-32512

Date
Nov 10, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin <= 3.7.1 versions.
Affected versions
Min -, max -.
Status
vulnerable

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization # CVE-2024-31230

CVE, Research URL

CVE-2024-31230

Date
Apr 10, 2024
Research Description
Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.2.
Affected versions
Min -, max -.
Status
vulnerable

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization # CVE-2024-4689

CVE, Research URL

CVE-2024-4689

Date
May 14, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.3.
Affected versions
Min -, max -.
Status
vulnerable
Apr 03, 2025

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization # CVE-2025-30853

CVE, Research URL

CVE-2025-30853

Date
Apr 02, 2025
Research Description
Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ShortPixel Adaptive Images: from n/a through 3.10.0.
Affected versions
Min -, max -.
Status
vulnerable
Aug 02, 2025

ShortPixel Adaptive Images &#8211; WebP, AVIF, CDN, Image Optimization # CVE-2025-6626

CVE, Research URL

CVE-2025-6626

Date
Aug 02, 2025
Research Description
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
Min -, max -.
Status
vulnerable