cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-smushit wp-smushit

Direction: ascending
Jun 07, 2024

Smush – Optimize, Compress and Lazy Load Images # CVE-2017-15079

CVE, Research URL

CVE-2017-15079

Date
Oct 06, 2017
Research Description
The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal.
Affected versions
max 2.7.6.
Status
vulnerable

Smush – Optimize, Compress and Lazy Load Images # CVE-2022-1009

CVE, Research URL

CVE-2022-1009

Date
May 30, 2022
Research Description
The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back in an admin page when uploading a malicious preset configuration, leading to a Reflected Cross-Site Scripting. For the attack to be successful, an attacker would need an admin to upload a malicious configuration file
Affected versions
max 3.9.9.
Status
vulnerable
Jun 22, 2024

Smush – Optimize, Compress and Lazy Load Images # CVE-2023-3352

CVE, Research URL

CVE-2023-3352

Date
Jun 21, 2024
Research Description
The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability check on the delete_resmush_list() function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to delete the resmush list for Nextgen or the Media Library.
Affected versions
max 3.16.5.
Status
vulnerable
Apr 02, 2025

Smush – Optimize, Compress and Lazy Load Images # CVE-2025-22288

CVE, Research URL

CVE-2025-22288

Date
Nov 06, 2025
Research Description
Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and Optimization wp-smushit allows Path Traversal.This issue affects Smush Image Compression and Optimization: from n/a through <= 3.17.0.
Affected versions
max 3.17.1.
Status
vulnerable
Jun 16, 2026

Smush &#8211; Optimize, Compress and Lazy Load Images # 41497e5826baf6a6bcedeca63643f2b334dba238

Date
Oct 09, 2017
Research Description
Smush – Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 2.7.6 WordPress Smush Image Compression and Optimization plugin <=2.7.5 - File Traversal vulnerability File Traversal vulnerability found by Ricardo Sánchez in WordPress Smush Image Compression and Optimization plugin (versions <=2.7.5).
Affected versions
max 2.7.6.
Status
vulnerable

Smush &#8211; Optimize, Compress and Lazy Load Images # 652cee930b4c5b4daf628ea8a9f3a802f0d99948

Date
Dec 10, 2018
Research Description
Smush – Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.0.0 WordPress Smush Image Compression and Optimization plugin <= 2.9.1 - Authenticated XSS & Phar Deserialization vulnerabilities Authenticated XSS & Phar Deserialization vulnerabilities found by RIPS Technologies in WordPress Smush Image Compression and Optimization plugin (versions <= 2.9.1).
Affected versions
max 3.0.0.
Status
vulnerable

Smush &#8211; Optimize, Compress and Lazy Load Images # 1b7b9063d6297ef0cf4d01b221d4e4da2c885eb9

Date
Dec 10, 2018
Research Description
Smush – Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.0.1 Smush – Lazy Load Images, Optimize & Compress Images <= 3.0.0 - Authenticated PHAR Deserialization The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 3.0.0. This makes it possible for authenticated attackers to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
Affected versions
max 3.0.1.
Status
vulnerable

Smush &#8211; Optimize, Compress and Lazy Load Images # a23c3a99b0a842dcbe6bec87be8b60c8ba8bf4da

Date
Dec 10, 2018
Research Description
Smush – Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.0.0 Smush – Lazy Load Images, Optimize & Compress Images <= 2.9.1 - Cross-Site Scripting The Smush – Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to Cross-Site Scripting leading in versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject malicious web scripts into the application.
Affected versions
max 3.0.0.
Status
vulnerable

Smush &#8211; Optimize, Compress and Lazy Load Images # b5bf5f41-aad3-45be-9cab-ab846b94003a

Date
-
Research Description
Smush – Image Optimization, Compression, Lazy Load, WebP &amp; CDN [wp-smushit] < 3.9.9 Smush Image Compression and Optimization &lt;= 2.9.1 - Authenticated Phar Deserialization The Smush &ndash; Lazy Load Images, Optimize &amp; Compress Images WordPress plugin was affected by an Authenticated Phar Deserialization security vulnerability.
Affected versions
max 3.9.9.
Status
vulnerable
Jul 28, 2026

Smush &#8211; Optimize, Compress and Lazy Load Images # PSC-2026-64676

PSC, Research URL

PSC-2026-64676

Date
Jul 28, 2026
Research Description
Image optimization plugins process files that become part of nearly every public page. Compression, format conversion, lazy loading, and CDN delivery all need careful handling of uploads, metadata, and generated URLs. Smush - Image Optimization, Compression, Lazy Load, WebP & CDN version 4.2.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64676, confirming that the plugin was reviewed from a secure code perspective with attention to image processing inputs, media permissions, generated formats, remote delivery settings, and public markup.
Affected versions
Min 4.2.0, max 4.2.0.
Status
SAFE & CERTIFIED